← All CVEs

CVE-2024-38473

high · 8.1

A public exploit / detection template exists

Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

8.1
CVSS
25.9%
EPSS (exploit prob.)
98th
EPSS percentile
2024-07-01
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Weaknesses

CWE-116

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, < 2.4.60
netappontap9

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-38473