CVE-2024-38476

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:netapp:clustered_data_ontap:9.0:*:*:*:*:*:*:*

History

03 Nov 2025, 22:17

Type Values Removed Values Added
References
  • () http://seclists.org/fulldisclosure/2024/Oct/11 -

Information

Published : 2024-07-01 19:15

Updated : 2025-11-03 22:17


NVD link : CVE-2024-38476

Mitre link : CVE-2024-38476

CVE.ORG link : CVE-2024-38476


JSON object : View

Products Affected

netapp

  • clustered_data_ontap

apache

  • http_server
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere

NVD-CWE-noinfo