CVE-2024-38474 Details
Description
Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.
A substitution encoding issue has been identified in the mod_rewrite module of Apache HTTP Server. This vulnerability affects versions 2.4.59 and earlier. It allows an attacker to execute scripts in directories permitted by the server's configuration, but not directly accessible via URL. The issue also involves the unintentional disclosure of scripts meant to be executed as CGI. The vulnerability arises from some RewriteRules that capture and substitute data unsafely, which could lead to unauthorized script execution or information disclosure.
Users are advised to upgrade to Apache HTTP Server version 2.4.60 or later, which addresses this vulnerability. After upgrading, some RewriteRules that previously captured and substituted data unsafely may require adjustment to include the 'UnsafeAllow3F' rewrite flag.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 9, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html | CVE | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20240712-0001/ | CVE | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/07/01/7 | CVE | |
| https://httpd.apache.org/security/vulnerabilities_24.html | [email protected] | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20240712-0001/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-116 | Improper Encoding or Escaping of Output | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache http server | >= 2.4.0, < 2.4.60 |
CPE
Remediation
| |
| netapp clustered data ontap | 9.0 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Mar 25, 2025 | CVE Modified | CISA-ADP |
| Nov 21, 2024 | CVE Modified | CVE |
| Aug 21, 2024 | Initial Analysis | [email protected] |
| Jul 12, 2024 | CVE Modified | [email protected] |
| Jul 1, 2024 | New CVE Received | [email protected] |