A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.
Users are recommended to upgrade to version 2.4.62, which fixes this issue.
References
Link | Resource |
---|---|
https://httpd.apache.org/security/vulnerabilities_24.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
22 Aug 2024, 17:13
Type | Values Removed | Values Added |
---|---|---|
References | () https://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:apache:http_server:2.4.61:*:*:*:*:*:*:* cpe:2.3:a:apache:http_server:2.4.60:*:*:*:*:*:*:* |
|
CWE | NVD-CWE-noinfo | |
First Time |
Apache
Apache http Server |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
18 Jul 2024, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-18 10:15
Updated : 2024-08-22 17:13
NVD link : CVE-2024-40725
Mitre link : CVE-2024-40725
CVE.ORG link : CVE-2024-40725
JSON object : View
Products Affected
apache
- http_server
CWE