peter bassill · operator
$ cve CVE-2024-38475 JSON

CVE-2024-38475 KEV

9.1
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-05-22.

Description

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS99.96% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-116
On CISA KEVyes — remediate by 2025-05-22
Public exploitnone known
Published2024-07-01
Last modified2026-06-17

CISA KEV

NameApache HTTP Server Improper Escaping of Output Vulnerability
Added2025-05-01
Due2025-05-22
Vendor / productApache / HTTP Server
Ransomware usenone reported

Affected (12)

VendorProduct
apachehttp server
netappontap 9
sonicwallsma 200
sonicwallsma 200 firmware
sonicwallsma 210
sonicwallsma 210 firmware
sonicwallsma 400
sonicwallsma 400 firmware
sonicwallsma 410
sonicwallsma 410 firmware
sonicwallsma 500v
sonicwallsma 500v firmware

References

→ the Explorer  ·  watch your stack  ·  NVD