CVE-2024-38473: exploitation status and patch state
CVE-2024-38473 · CVSS 8.1 HIGH · EPSS 26%
Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
Is CVE-2024-38473 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 26%.
Public exploit code: none found in monitored sources.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2024-38473
PlainSec has not published a story about this CVE.