Lucene search

K
hackeroneOrangeH1:2585384
HistoryJul 03, 2024 - 7:01 a.m.

Internet Bug Bounty: moderate: Apache HTTP Server proxy encoding problem (CVE-2024-38473)

2024-07-0307:01:22
orange
hackerone.com
$2600
21
apache http server
mod_proxy
encoding problem
cve-2024-38473
backend services
authentication bypass
upgrade
bug bounty

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7

Confidence

Low

I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html

Impact

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.

Users are recommended to upgrade to version 2.4.60, which fixes this issue.

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7

Confidence

Low