ZeroHour

CVE-2024-24795

CVSS 3.1
6.3 medium
EPSS
3%p86
Published
()
Modified
Description

HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.

Vendors
apachedebianfedoraprojectnetappbroadcomapple
Products
http server, debian linux, fedora, ontap, ontap tools, fabric operating system, macos
Weakness
CWE-113, CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.