important: Apache HTTP Server: Crash resulting in Denial of Service in mod_proxy via a malicious request (CVE-2024-38477)

Disclosed: 2024-07-13 14:36:11 By orange To ibb
High
Vulnerability Details
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there: > https://httpd.apache.org/security/vulnerabilities_24.html ## Impact null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Actions
View on HackerOne
Report Stats
  • Report ID: 2585375
  • State: Closed
  • Substate: resolved
  • Upvotes: 26
Share this report