CVE-2024-24795

Apache HTTP Server regression

Beschreibung

Eine HTTP-Antwortaufspaltung in mehreren Modulen im Apache HTTP Server ermöglicht es einem Angreifer, der schädliche Antwortheader in Backend-Anwendungen injizieren kann, einen HTTP-Desynchronisationsangriff durchzuführen. Es wird Benutzern empfohlen, auf Version 2.4.59 zu aktualisieren, die dieses Problem behebt.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
6.3
Quelle: nvd-v3
86.0 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
2.9 %
Moderat — Modell schätzt 1-10 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-29 10:47 UTC
CWE-113

Weakness-Klassen (CWE)

  • CWE-113Variant

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

    The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    debian / debian_linux10.0

  • macos

    apple / macos

  • other

    netapp / clustered_data_ontap9.0

  • other

    broadcom / fabric_operating_system

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

  • other

    fedoraproject / fedora39

  • other

    fedoraproject / fedora40

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.7

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2024-24795
Apache HTTP Server regression — CVE-2024-24795 | NEOSEC Intel