CVE-2024-39573

Apache HTTP Server regression

Beschreibung

Mögliche SSRF in mod_rewrite im Apache HTTP Server 2.4.59 und früher ermöglicht es einem Angreifer, unsichere RewriteRules unerwartet so einzurichten, dass URLs von mod_proxy verarbeitet werden. Benutzer werden empfohlen, auf Version 2.4.60 zu aktualisieren, die dieses Problem behebt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
98.4 %
Kritisch — CVE liegt im obersten Fünftel aller heute bewerteten CVEs (Rang ≥ 80 %).
37.2 %
Erhöht — Modell schätzt 10-50 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-29 10:47 UTC
CWE-20

Weakness-Klassen (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    debian / debian_linux10.0

  • macos

    apple / macos

  • other

    netapp / clustered_data_ontap9.0

  • other

    broadcom / fabric_operating_system

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

  • other

    fedoraproject / fedora39

  • other

    fedoraproject / fedora40

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.7

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2024-39573