You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2024 38473
About this tag
CVE-2024-38473 is a disclosed vulnerability in the Apache HTTP Server's mod_proxy module. It stems from an encoding flaw that allows crafted requests to bypass intended authentication checks and reach backend services, potentially exposing protected resources. The fix is included in Apache HTTP Server version 2.4.60. Operators should treat this as an urgent configuration and patch-management issue and update affected servers immediately. The tag covers discussion of the vulnerability's background, impact, and remediation steps for Windows and other platforms running Apache.
An encoding flaw in Apache HTTP Server’s mod_proxy can let crafted requests slip past intended authentication checks and reach backend services, potentially exposing protected resources — operators should treat this as an urgent configuration and patch-management issue and update affected...