Site icon API Security Blog

K000140618: Apache HTTPD vulnerability CVE-2024-38476

Security Advisory Description Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue. (CVE-2024-38476) Impact When the vulnerability is exploited, the affected Apache HTTP service may disclose sensitive information, add/modify data, or experience denial of service…Read More

Exit mobile version