CVE-2024-47252: Apache HTTP Server: mod_ssl error log variable escaping
Published Jun 24, 2025
·Updated
Insufficient escaping of user-supplied data in modssl in Apache HTTP Server 2.4.63 and earlier allows an untrusted SSL/TLS client to insert escape characters into log files in some configurations.
Affected Software
9 affected componentsFixes available
Apache HTTP Server<2.4.63
Apache HTTP Server>=2.4.0<2.4.64
IBM Cloud Pak System<=2.3.4.0
IBM Cloud Pak System<=2.3.4.1
2.3.4.1 ifix1
IBM Cloud Pak System<=2.3.5.0
IBM Cloud Pak System<=2.3.6.0
IBM OS Image for Red Hat Linux Systems<=4.0.4.0
4.0.5.0
4.0.6.0
4.0.7.0
IBM OS Image for Red Hat Linux Systems<=5.0.0.0
5.0.1.0
debian/apache2<=2.4.62-1~deb11u1
2.4.67-1~deb11u12.4.67-1~deb12u22.4.67-1~deb13u22.4.67-1
Event History
Jun 24, 2025
Data Sourced
via Red Hat·01:15 PM
DescriptionSeverityAffected Software
Jul 10, 2025
CVE Published
via MITRE·04:55 PM
Data Sourced
via MITRE·04:55 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Jan 30, 2026
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
May 28, 2026
Data Sourced
via Ubuntu·06:16 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·06:16 PM
DescriptionAffected Software
Data Sourced
via Launchpad·06:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-47252?
CVE-2024-47252 has been classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-47252?
To fix CVE-2024-47252, upgrade to Apache HTTP Server version 2.4.64 or later, which includes patches for this vulnerability.
3
What impact does CVE-2024-47252 have on my Apache server?
CVE-2024-47252 allows untrusted SSL/TLS clients to manipulate log files, potentially leading to misleading information in logs.
4
What versions of Apache HTTP Server are affected by CVE-2024-47252?
CVE-2024-47252 affects Apache HTTP Server versions 2.4.63 and earlier.
5
Is CVE-2024-47252 related to SSL/TLS security?
Yes, CVE-2024-47252 involves insufficient escaping of user-supplied data in the context of SSL/TLS clients.