Vulnerability CVE-2024-39573: Information

Description

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Published: July 1, 2024
Modified: July 12, 2024
Error type identifier: CWE-20

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
apache2sisyphus2.4.61-alt12.4.61-alt1ALT-PU-2024-9736-1352421Fixed
apache2sisyphus_riscv642.4.61-alt12.4.61-alt1ALT-PU-2024-9756-1-Fixed
apache2sisyphus_loongarch642.4.61-alt12.4.61-alt1ALT-PU-2024-9761-1-Fixed
apache2p112.4.61-alt12.4.59-alt1ALT-PU-2024-9738-1352426Testing

References to Advisories, Solutions, and Tools