Severity: moderate

Affected versions:

- Apache HTTP Server 2.4.0 through 2.4.59

Description:

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows 
request URLs with incorrect encoding to be sent to backend services, 
potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Credit:

Orange Tsai (@orange_8361) from DEVCORE (finder)

References:

https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-38473

Timeline:

2024-04-01: reported

Reply via email to