Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://httpd.apache.org/security/vulnerabilities_24.html | Vendor Advisory |
https://security.netapp.com/advisory/ntap-20240712-0001/ | Third Party Advisory |
https://security.netapp.com/advisory/ntap-20240712-0001/ | Third Party Advisory |
http://www.openwall.com/lists/oss-security/2024/07/01/6 | Mailing List |
https://httpd.apache.org/security/vulnerabilities_24.html | Vendor Advisory |
Configurations
History
01 Jul 2025, 20:25
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* |
|
First Time |
Netapp
Netapp ontap Apache http Server Apache |
|
CWE | ||
References |
|
|
References | () https://security.netapp.com/advisory/ntap-20240712-0001/ - Third Party Advisory | |
References | () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory |
12 Jul 2024, 14:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
01 Jul 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-01 19:15
Updated : 2025-07-01 20:25
NVD link : CVE-2024-38473
Mitre link : CVE-2024-38473
JSON object : View
Products Affected
apache
- http_server
netapp
- ontap
CWE
No CWE.