CVE-2024-38476: Apache HTTP Server may use exploitable/malicious backend application output to run local handlers via internal redirect
Apache. This is a vulnerability in open source code and Apple Software among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
Other sources
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
— Red Hat
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-39573
- CVE-2024-38477
- CVE-2024-38476
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-44270
- CVE-2024-44280
- CVE-2024-44260
- CVE-2024-54535
- CVE-2024-44298
- CVE-2024-44273
- CVE-2024-44295
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-54554
- CVE-2024-44213
- CVE-2024-44289
- CVE-2024-44282
- CVE-2024-44265
- CVE-2024-40854
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44216
- CVE-2024-44287
- CVE-2024-44197
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-44285
- CVE-2024-44239
- CVE-2024-44286
- CVE-2024-40849
- CVE-2024-44201
- CVE-2024-44231
- CVE-2024-44223
- CVE-2024-44222
- CVE-2024-44256
- CVE-2024-54471
- CVE-2024-44292
- CVE-2024-44293
- CVE-2024-44247
- CVE-2024-44267
- CVE-2024-44301
- CVE-2024-44275
- CVE-2024-44303
- CVE-2024-44156
- CVE-2024-44159
- CVE-2024-44253
- CVE-2024-44294
- CVE-2024-44196
- CVE-2024-40858
- CVE-2024-44277
- CVE-2024-44195
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44219
- CVE-2024-44211
- CVE-2024-44218
- CVE-2024-44248
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-44236
- CVE-2024-44237
- CVE-2024-44279
- CVE-2024-44281
- CVE-2024-44283
- CVE-2024-44284
- CVE-2024-44194
- CVE-2024-44200
- CVE-2024-44278
- CVE-2024-44210
- CVE-2024-44264
- CVE-2024-44290
- CVE-2024-44296
- CVE-2024-44212
- CVE-2024-44244
- CVE-2024-44257
- CVE-2024-44250
Frequently Asked Questions
What is the severity of CVE-2024-38476?
CVE-2024-38476 has been rated with high severity due to its impact on the core of Apache HTTP Server versions 2.4.59 and earlier.
How do I fix CVE-2024-38476?
To fix CVE-2024-38476, update Apache HTTP Server to version 2.4.62-1~deb11u1 or later.
What versions of Apache HTTP Server are affected by CVE-2024-38476?
CVE-2024-38476 affects Apache HTTP Server versions 2.4.59 and earlier.
Which operating systems are impacted by CVE-2024-38476?
CVE-2024-38476 impacts multiple operating systems, including Debian and macOS Sequoia.
Is there a workaround for CVE-2024-38476?
Currently, the recommended mitigation for CVE-2024-38476 is to upgrade to the latest version of Apache HTTP Server.