CVE-2024-38476
CRITICALApache HTTP Server <2.4.60 - Info Disclosure/SSRF
Title source: llmDescription
Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Exploits (2)
github
SCANNER
123 stars
by mrmtwoj · pythonpoc
https://github.com/mrmtwoj/apache-vulnerability-testing
nomisec
WRITEUP
by abanop22333 · poc
https://github.com/abanop22333/Apache-Authentication-Flaw-Research-CVE-2024-38476-
References (4)
Scores
CVSS v3
9.8
EPSS
0.0467
EPSS Percentile
89.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-829
Status
published
Products (2)
apache/http_server
2.4.0 - 2.4.60
netapp/clustered_data_ontap
9.0
Published
Jul 01, 2024
Tracked Since
Feb 18, 2026