Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-38477


null pointer dereference in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows an attacker to crash the server via a malicious request. Users are recommended to upgrade to version 2.4.60, which fixes this issue.


Published

2024-07-01T19:15:05.083

Last Modified

2025-03-18T19:15:42.683

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Primary
    CWE-476

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache http_server < 2.4.60 Yes
Operating System netapp clustered_data_ontap 9.0 Yes

References