Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
CVE ID: CVE-2024-38473
Vendor: Apache Software Foundation
Product: Apache HTTP Server
http/cves/2024/CVE-2024-38473.yaml
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 28.37% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)