CVE-2024-38474

Updated: 2025-08-20 01:43:46.959614

Description:

Substitution encoding issue in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows attacker to execute scripts in directories permitted by the configuration but not directly reachable by any URL or source disclosure of scripts meant to only to be executed as CGI. Users are recommended to upgrade to version 2.4.60, which fixes this issue. Some RewriteRules that capture and substitute unsafely will now fail unless rewrite flag "UnsafeAllow3F" is specified.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x CRITICAL 9.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Oracle Linux 7 ELS httpd 2.4.6 9.8 CRITICAL Already Fixed 2024-12-03 12:09:58
RHEL 7 ELS httpd 2.4.6 9.8 CRITICAL Released CLSA-2025:1748638011 2025-06-02 16:07:05
Ubuntu 16.04 ELS apache2 2.4.18 9.8 CRITICAL Released CLSA-2024:1725012024 2024-08-30 12:14:43
Ubuntu 18.04 ELS apache2 2.4.29 9.8 CRITICAL Released CLSA-2024:1724788546 2024-08-27 17:27:28
Total: 14