Alpaquita LinuxStreamSecurity Advisory
Search Cve

CVE-2024-38473

Published: July 2, 2024Last modified: July 5, 2024

Description

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Severity score breakdown

ParameterValue
Base score8.1
Attack VectorNETWORK
Attack complexityLOW
Privileges requiredLOW
User interactionNONE
ScopeUNCHANGED
ConfidentialityHIGH
Integrity impactNONE
Availability impactHIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Status

ProductReleasePackageStatus
Alpaquita Linux23 LTSapache2Fixed (2.4.61-r0)
Streamapache2Fixed (2.4.61-r0)

References

Published BELL-SAs

ON THIS PAGE