← Back to browse · API

CVE-2024-39573

Severity
HIGH
CVSS
7.5
EPSS
0.35447
Risk score
42.41
CISA KEV
No
PoC
Yes
Published
2024-07-01
Modified
2025-11-03
First seen
2026-08-07
Aliases
EUVD-2024-38096, GHSA-2WCW-RCF9-QM36
Products
Apache Software Foundation:Apache HTTP Server 2.4.0 ≤2.4.59, linux, suse
Sources
packetstorm 6ed36f584bdbf7e8f0001469|CVE-2024-39573
euvd EUVD-2024-38096

Description

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

References