CVE-2024-43204

Apache HTTP Server regression

Beschreibung

SSRF im Apache HTTP Server mit geladenem mod_proxy ermöglicht es einem Angreifer, ausgehende Proxy-Anfragen an eine vom Angreifer kontrollierte URL zu senden. Erfordert eine unwahrscheinliche Konfiguration, bei der mod_headers so konfiguriert ist, dass er den Content-Type-Request- oder Antwortheader mit einem Wert ändert, der im HTTP-Anfrage bereitgestellt wird. Es wird Benutzern empfohlen, auf Version 2.4.64 zu aktualisieren, die dieses Problem behebt.

Metriken

Severity
high
kein öffentlicher PoC bekannt
7.5
Quelle: nvd-v3
54.8 %
Hoch — CVE rangiert über dem Median aller heute bewerteten CVEs (Rang ≥ 36 %).
0.8 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-05-29 10:47 UTC
CWE-918

Weakness-Klassen (CWE)

  • CWE-918Base

    Server-Side Request Forgery (SSRF)

    The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

    cwe.mitre.org →

Betroffene Betriebssysteme

  • linux

    debian / debian_linux10.0

  • macos

    apple / macos

  • other

    netapp / clustered_data_ontap9.0

  • other

    broadcom / fabric_operating_system

  • other

    fedoraproject / fedora37

  • other

    fedoraproject / fedora38

  • other

    fedoraproject / fedora39

  • other

    fedoraproject / fedora40

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • bitnami

    apache2.4.0

  • bitnami

    apache2.4.17

  • bitnami

    apache2.4.30

  • bitnami

    apache2.4.7

  • bitnami

    apache

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2024-43204