CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2024-38475

CVSS 9.1v3.1pub. 2024-07-01upd. 2025-11-17

Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected.  Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.

🤖 AI Analysis
How it works

The mod_rewrite module incorrectly processes special characters during substitution in the server context, when the first segment of the substitution is a backreference or variable. This allows an attacker to construct a specially crafted URL that is mapped to a file system location accessible to the server but normally unreachable through any public URL. The consequence can be both source code disclosure and code execution on the server. The vendor introduced a new RewriteRule flag called 'UnsafePrefixStat', allowing administrators to restore the previous behavior after ensuring the security of the applied rules.

Impact

An attacker can gain unauthorized access to server system files (source code disclosure) or cause remote code execution (RCE) without the need for authentication.

Mitigation & patch

Update Apache HTTP Server to a version higher than 2.4.59 as soon as possible, applying patches indicated by the vendor at https://httpd.apache.org/security/vulnerabilities_24.html. Administrators using unsafe RewriteRule rules should verify their correctness before any potential use of the 'UnsafePrefixStat' flag. For NetApp and SonicWall products, apply patches available from the vendor according to the references.

Who is affected

Apache HTTP Server versions 2.4.59 and earlier; dependent products: NetApp ONTAP 9, SonicWall SMA 200 Firmware, SonicWall SMA 200, SonicWall SMA 210 Firmware

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Apache HTTP Server

    APP
    Apache
    2.4.0 – 2.4.60 (excl.)
  • Netapp Ontap 9

    APP
    Netapp
    all versions
  • Sonicwall Sma 200

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 200 Firmware

    OS
    Sonicwall
    < 10.2.1.14-75sv
  • Sonicwall Sma 210

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 210 Firmware

    OS
    Sonicwall
    < 10.2.1.14-75sv
  • Sonicwall Sma 400

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 400 Firmware

    OS
    Sonicwall
    < 10.2.1.14-75sv
  • Sonicwall Sma 410

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 410 Firmware

    OS
    Sonicwall
    < 10.2.1.14-75sv
  • Sonicwall Sma 500v

    HW
    Sonicwall
    all versions
  • Sonicwall Sma 500v Firmware

    OS
    Sonicwall
    < 10.2.1.14-75sv

CISA KEV — detailsi

Vendori
Apache
Producti
HTTP Server
Added to KEVi
May 1, 2025
Remediation deadline (US Federal)i
May 22, 2025(overdue)
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

Apache HTTP Server contains an improper escaping of output vulnerability in mod_rewrite that allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
CISA DEADLINE: 22 maja 2025
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2021-20038CRITICAL9.8⚠ KEVPL ✓same product

Stack-based buffer overflow w SonicWall SMA 100 — zdalny RCE bez uwierzytelnienia

CVE-2021-42013CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.50 — path traversal i RCE (niewystarczający patch CVE-2021-41773)

CVE-2021-41773CRITICAL9.8⚠ KEVPL ✓same product

Apache HTTP Server 2.4.49 — path traversal i RCE (aktywnie exploitowany)

CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓same product

SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego

CVE-2021-20028CRITICAL9.8⚠ KEVPL ✓same product

SQL Injection w urządzeniach SonicWall SRA/SMA — zdalne przejęcie kontroli