CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2024-39884: Apache HTTP Server: source code disclosure with handlers configured via AddType

Description

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the legacy content-type based configuration of handlers.   "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.

Users are recommended to upgrade to version 2.4.61, which fixes this issue.

Classification

CVE ID: CVE-2024-39884

Affected Products

Vendor: Apache Software Foundation

Product: Apache HTTP Server

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 18.39% (scored less or equal to compared to others)

EPSS Date: 2025-03-14 (when was this score calculated)

References

https://httpd.apache.org/security/vulnerabilities_24.html
https://security.netapp.com/advisory/ntap-20240712-0002/
http://www.openwall.com/lists/oss-security/2024/07/17/6

Timeline