moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)
Medium
Vulnerability Details
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Actions
View on HackerOneReport Stats
- Report ID: 2585384
- State: Closed
- Substate: resolved
- Upvotes: 15