CVE-2024-38473: Apache HTTP Server proxy encoding problem
Apache HTTP Server could allow a remote attacker to bypass security restrictions, caused by an encoding flaw in modproxy. By sending specially crafted requests with incorrect encoding an attacker could exploit this vulnerability to bypass authentication validation.
Other sources
Encoding problem in modproxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
— NVD
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38473?
CVE-2024-38473 has been classified with a high severity due to its potential to allow remote attackers to bypass authentication.
How do I fix CVE-2024-38473?
To fix CVE-2024-38473, update your Apache HTTP Server to patched versions 2.4.62-1~deb11u1, 2.4.61-1~deb11u1, or higher.
Which software is affected by CVE-2024-38473?
CVE-2024-38473 affects Apache HTTP Server, IBM Planning Analytics, and various F5 products including F5OS-A and Traffix SDC.
Can CVE-2024-38473 be exploited remotely?
Yes, CVE-2024-38473 can be exploited remotely by attackers sending specially crafted requests.
What kind of attacks can CVE-2024-38473 facilitate?
CVE-2024-38473 can facilitate authentication bypass attacks due to an encoding flaw in mod_proxy.