Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
History

Fri, 13 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 13 Aug 2024 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat jboss Core Services
CPEs cpe:/a:redhat:jboss_core_services:1
cpe:/a:redhat:jboss_core_services:1::el7
cpe:/a:redhat:jboss_core_services:1::el8
Vendors & Products Redhat jboss Core Services

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2024-07-01T18:14:21.520Z

Updated: 2024-09-13T17:04:54.566Z

Reserved: 2024-06-17T11:05:01.135Z

Link: CVE-2024-38473

cve-icon Vulnrichment

Updated: 2024-09-13T17:04:54.566Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-07-01T19:15:04.657

Modified: 2024-11-21T09:26:02.607

Link: CVE-2024-38473

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-07-01T00:00:00Z

Links: CVE-2024-38473 - Bugzilla