CVE-2024-38476

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:netapp:clustered_data_ontap:9.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-07-01 19:15

Updated : 2024-12-02 17:36


NVD link : CVE-2024-38476

Mitre link : CVE-2024-38476

CVE.ORG link : CVE-2024-38476


JSON object : View

Products Affected

apache

  • http_server

netapp

  • clustered_data_ontap
CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere

NVD-CWE-noinfo