CVE-2024-38473

Apache HTTP Server regression

Beschreibung

Ein Kodierungsproblem in mod_proxy im Apache HTTP Server 2.4.59 und früher ermöglicht es, Anfrage-URLs mit falscher Kodierung an Backend-Dienste zu senden, was potenziell die Authentifizierung durch gefälschte Anfragen umgangen werden kann. Es wird empfohlen, auf Version 2.4.60 zu aktualisieren, die dieses Problem behebt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
8.1
Quelle: nvd-v3
97.9 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
25.9 %
Erhöht — Modell schätzt 10-50 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-29 10:47 UTC
CWE-116

Weakness-Klassen (CWE)

  • CWE-116Class

    Improper Encoding or Escaping of Output

    The product prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    debian / debian_linux10.0

  • macos

    apple / macos

  • other

    netapp / clustered_data_ontap9.0

  • other

    broadcom / fabric_operating_system

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

  • other

    fedoraproject / fedora39

  • other

    fedoraproject / fedora40

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.7

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2024-38473