Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-24795


HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.


Published

2024-04-04T20:15:08.663

Last Modified

2025-06-30T12:55:47.280

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-113
  • Type: Secondary
    CWE-444

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache http_server < 2.4.59 Yes
Operating System debian debian_linux 10.0 Yes
Operating System fedoraproject fedora 38 Yes
Operating System fedoraproject fedora 39 Yes
Operating System fedoraproject fedora 40 Yes
Application netapp ontap 9 Yes
Application netapp ontap_tools 10 Yes
Operating System broadcom fabric_operating_system - Yes
Operating System apple macos < 14.6 Yes

References