mirror of
https://github.com/fkie-cad/nvd-json-data-feeds.git
synced 2025-05-28 09:11:28 +00:00
41 lines
1.5 KiB
JSON
41 lines
1.5 KiB
JSON
{
|
|
"id": "CVE-2024-38476",
|
|
"sourceIdentifier": "security@apache.org",
|
|
"published": "2024-07-01T19:15:04.977",
|
|
"lastModified": "2024-07-12T14:15:15.360",
|
|
"vulnStatus": "Awaiting Analysis",
|
|
"cveTags": [],
|
|
"descriptions": [
|
|
{
|
|
"lang": "en",
|
|
"value": "Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via\u00a0backend applications whose response headers are malicious or exploitable.\n\nUsers are recommended to upgrade to version 2.4.60, which fixes this issue."
|
|
},
|
|
{
|
|
"lang": "es",
|
|
"value": "La vulnerabilidad en el n\u00facleo de Apache HTTP Server 2.4.59 y versiones anteriores es vulnerable a la divulgaci\u00f3n de informaci\u00f3n, SSRF o ejecuci\u00f3n de scripts locales a trav\u00e9s de aplicaciones backend cuyos encabezados de respuesta son maliciosos o explotables. Se recomienda a los usuarios actualizar a la versi\u00f3n 2.4.60, que soluciona este problema."
|
|
}
|
|
],
|
|
"metrics": {},
|
|
"weaknesses": [
|
|
{
|
|
"source": "security@apache.org",
|
|
"type": "Primary",
|
|
"description": [
|
|
{
|
|
"lang": "en",
|
|
"value": "CWE-829"
|
|
}
|
|
]
|
|
}
|
|
],
|
|
"references": [
|
|
{
|
|
"url": "https://httpd.apache.org/security/vulnerabilities_24.html",
|
|
"source": "security@apache.org"
|
|
},
|
|
{
|
|
"url": "https://security.netapp.com/advisory/ntap-20240712-0001/",
|
|
"source": "security@apache.org"
|
|
}
|
|
]
|
|
} |