CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-38473: Apache HTTP Server proxy encoding problem

Description

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Classification

CVE ID: CVE-2024-38473

Affected Products

Vendor: Apache Software Foundation

Product: Apache HTTP Server

Nuclei Template

http/cves/2024/CVE-2024-38473.yaml

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 28.37% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://httpd.apache.org/security/vulnerabilities_24.html
https://security.netapp.com/advisory/ntap-20240712-0001/

Timeline