CVE-2024-38475 vulnerability in Canonical and Other Products
Published on July 1, 2024





Known Exploited Vulnerability
This Apache HTTP Server Improper Escaping of Output Vulnerability is part of CISA's list of Known Exploited Vulnerabilities. Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.
The following remediation steps are recommended / required by May 22, 2025: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Vulnerability Analysis
Products Associated with CVE-2024-38475
You can be notified by stack.watch whenever vulnerabilities like CVE-2024-38475 are published in these products:
What versions are vulnerable to CVE-2024-38475?
-
Apache HTTP Server Version 2.4.0 Fixed in Version 2.4.60
-
NetApp Ontap 9 Version -