← All CVEs

CVE-2024-38476

critical · 9.8

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

9.8
CVSS
41.6%
EPSS (exploit prob.)
99th
EPSS percentile
2024-07-01
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-829

Affected products

VendorProductAffected versions
apachehttp_server>= 2.4.0, < 2.4.60
netappclustered_data_ontap9.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2024-38476