CVE-2024-39573

Publication date 1 July 2024

Last updated 24 July 2024


Ubuntu priority

Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Read the notes from the security team

Status

Package Ubuntu Release Status
apache2 24.10 oracular
Fixed 2.4.62-1ubuntu1
24.04 LTS noble
Fixed 2.4.58-1ubuntu8.2
23.10 mantic
Fixed 2.4.57-2ubuntu2.5
22.04 LTS jammy
Fixed 2.4.52-1ubuntu4.10
20.04 LTS focal
Fixed 2.4.41-4ubuntu3.19
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty Ignored end of ESM support, was needs-triage

Notes


mdeslaur

Same commit as one of the ones listed in CVE-2024-38473

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
apache2