{"dataType":"CVE_RECORD","cveMetadata":{"cveId":"CVE-2024-38473","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2024-06-17T11:05:01.135Z","datePublished":"2024-07-01T18:14:21.520Z","dateUpdated":"2025-02-13T17:53:12.372Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache HTTP Server","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.4.59","status":"affected","version":"2.4.0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Orange Tsai (@orange_8361) from DEVCORE"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.<br>Users are recommended to upgrade to version 2.4.60, which fixes this issue."}],"value":"Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue."}],"metrics":[{"other":{"content":{"text":"moderate"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-116","description":"CWE-116 Improper Encoding or Escaping of Output","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2024-07-12T14:06:08.211Z"},"references":[{"tags":["vendor-advisory"],"url":"https://httpd.apache.org/security/vulnerabilities_24.html"},{"url":"https://security.netapp.com/advisory/ntap-20240712-0001/"}],"source":{"discovery":"UNKNOWN"},"timeline":[{"lang":"en","time":"2024-04-01T12:00:00.000Z","value":"reported"}],"title":"Apache HTTP Server proxy encoding problem","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"affected":[{"vendor":"apache_software_foundation","product":"apache_http_server","cpes":["cpe:2.3:a:apache_software_foundation:apache_http_server:*:*:*:*:*:*:*:*"],"defaultStatus":"unaffected","versions":[{"version":"2.4.0","status":"affected","lessThanOrEqual":"2.4.59","versionType":"semver"}]}],"metrics":[{"cvssV3_1":{"scope":"UNCHANGED","version":"3.1","baseScore":8.1,"attackVector":"NETWORK","baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","integrityImpact":"NONE","userInteraction":"NONE","attackComplexity":"LOW","availabilityImpact":"HIGH","privilegesRequired":"LOW","confidentialityImpact":"HIGH"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-07-24T13:55:35.300035Z","id":"CVE-2024-38473","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-07-24T14:02:38.927Z"}},{"title":"CVE Program Container","references":[{"tags":["vendor-advisory","x_transferred"],"url":"https://httpd.apache.org/security/vulnerabilities_24.html"},{"url":"https://security.netapp.com/advisory/ntap-20240712-0001/","tags":["x_transferred"]},{"url":"http://www.openwall.com/lists/oss-security/2024/07/01/6"}],"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-09-13T17:04:54.566Z"}}]},"dataVersion":"5.1"}