CVE-2024-38473
high · 8.1A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
8.1
CVSS
25.9%
EPSS (exploit prob.)
98th
EPSS percentile
2024-07-01
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Weaknesses
CWE-116
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | http_server | >= 2.4.0, < 2.4.60 |
| netapp | ontap | 9 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2024-38473