CVE-2024-38475 KEV
9.1
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-05-22.
Description
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 99.96% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-116 |
| On CISA KEV | yes — remediate by 2025-05-22 |
| Public exploit | none known |
| Published | 2024-07-01 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Apache HTTP Server Improper Escaping of Output Vulnerability |
|---|---|
| Added | 2025-05-01 |
| Due | 2025-05-22 |
| Vendor / product | Apache / HTTP Server |
| Ransomware use | none reported |
Affected (12)
| Vendor | Product |
|---|---|
| apache | http server |
| netapp | ontap 9 |
| sonicwall | sma 200 |
| sonicwall | sma 200 firmware |
| sonicwall | sma 210 |
| sonicwall | sma 210 firmware |
| sonicwall | sma 400 |
| sonicwall | sma 400 firmware |
| sonicwall | sma 410 |
| sonicwall | sma 410 firmware |
| sonicwall | sma 500v |
| sonicwall | sma 500v firmware |
References
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://security.netapp.com/advisory/ntap-20240712-0001/
- http://www.openwall.com/lists/oss-security/2024/07/01/8
- https://github.com/apache/httpd/commit/9a6157d1e2f7ab15963020381054b48782bc18cf
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2024-0018
- https://security.netapp.com/advisory/ntap-20240712-0001/
- https://www.blackhat.com/us-24/briefings/schedule/index.html#confusion-attacks-exploiting-hidden-semantic-ambiguity-in-apache-http-server-pre-recorded-40227
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-38475
→ the Explorer · watch your stack · NVD