CVE-2024-39573: Apache HTTP Server: mod_rewrite proxy handler substitution
Apache HTTP Server is vulnerable to server-side request forgery, caused by a flaw in the modrewrite. By sending a specially crafted request, an attacker could exploit this vulnerability to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by modproxy.
Other sources
Apache. This is a vulnerability in open source code and Apple Software among the affected projects. The CVE-ID was assigned by a third party. Learn more about the issue and CVE-ID at cve.org.
— Apple
Potential SSRF in modrewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by modproxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
— Red Hat
Credit
Affected Software
Remediation
Patch Available
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2024-39573
- CVE-2024-38477
- CVE-2024-38476
- CVE-2024-44255
- CVE-2024-44232
- CVE-2024-44233
- CVE-2024-44234
- CVE-2024-44270
- CVE-2024-44280
- CVE-2024-44260
- CVE-2024-54535
- CVE-2024-44298
- CVE-2024-44273
- CVE-2024-44295
- CVE-2024-44240
- CVE-2024-44302
- CVE-2024-54554
- CVE-2024-44213
- CVE-2024-44289
- CVE-2024-44282
- CVE-2024-44265
- CVE-2024-40854
- CVE-2024-44215
- CVE-2024-44297
- CVE-2024-44216
- CVE-2024-44287
- CVE-2024-44197
- CVE-2024-44299
- CVE-2024-44241
- CVE-2024-44242
- CVE-2024-44238
- CVE-2024-44285
- CVE-2024-44239
- CVE-2024-44286
- CVE-2024-40849
- CVE-2024-44201
- CVE-2024-44231
- CVE-2024-44223
- CVE-2024-44222
- CVE-2024-44256
- CVE-2024-54471
- CVE-2024-44292
- CVE-2024-44293
- CVE-2024-44247
- CVE-2024-44267
- CVE-2024-44301
- CVE-2024-44275
- CVE-2024-44303
- CVE-2024-44156
- CVE-2024-44159
- CVE-2024-44253
- CVE-2024-44294
- CVE-2024-44196
- CVE-2024-40858
- CVE-2024-44277
- CVE-2024-44195
- CVE-2024-44259
- CVE-2024-44229
- CVE-2024-44219
- CVE-2024-44211
- CVE-2024-44218
- CVE-2024-44248
- CVE-2024-54538
- CVE-2024-44254
- CVE-2024-44269
- CVE-2024-44236
- CVE-2024-44237
- CVE-2024-44279
- CVE-2024-44281
- CVE-2024-44283
- CVE-2024-44284
- CVE-2024-44194
- CVE-2024-44200
- CVE-2024-44278
- CVE-2024-44210
- CVE-2024-44264
- CVE-2024-44290
- CVE-2024-44296
- CVE-2024-44212
- CVE-2024-44244
- CVE-2024-44257
- CVE-2024-44250
Frequently Asked Questions
What is the severity of CVE-2024-39573?
CVE-2024-39573 is classified as a high severity vulnerability due to the potential for server-side request forgery.
How do I fix CVE-2024-39573?
To fix CVE-2024-39573, upgrade to the patched versions of Apache HTTP Server or affected products as specified by the vendor.
What products are affected by CVE-2024-39573?
CVE-2024-39573 affects several products, including Apache HTTP Server versions prior to 2.4.62, IBM Planning Analytics, and various versions of F5 BIG-IP.
What is server-side request forgery in the context of CVE-2024-39573?
In CVE-2024-39573, server-side request forgery allows an attacker to make unauthorized requests to internal resources through manipulated RewriteRules.
Can I still use my web applications if they are vulnerable to CVE-2024-39573?
Using web applications vulnerable to CVE-2024-39573 poses significant security risks, and it is highly recommended to apply the necessary updates immediately.