CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-38477: Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request

Description

null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Classification

CVE ID: CVE-2024-38477

Affected Products

Vendor: Apache Software Foundation

Product: Apache HTTP Server

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.13% (probability of being exploited)

EPSS Percentile: 48.72% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://httpd.apache.org/security/vulnerabilities_24.html
https://security.netapp.com/advisory/ntap-20240712-0001/

Timeline