EUVD-2024-37356
Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 1 May 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.1 · CVSS 3.1
- Advisory evidence
- 25 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_redhat · RHSA-2024:4820Red Hat Security Advisory: httpd:2.4 security update
- csaf_redhat · RHSA-2024:4938Red Hat Security Advisory: httpd security update
- csaf_suse · SUSE-SU-2024:2591-1Security update for apache2
- csaf_ncscnl · NCSC-2025-0027Kwetsbaarheden verholpen in Oracle Fusion Middleware
- csaf_redhat · RHSA-2024:4726Red Hat Security Advisory: httpd security update
- csaf_suse · SUSE-SU-2024:2597-1Security update for apache2
- csaf_redhat · RHSA-2024:5240Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP5 security update
- csaf_ncscnl · NCSC-2024-0275Kwetsbaarheden verholpen in Apache HHTP-server
- csaf_redhat · RHSA-2024:4720Red Hat Security Advisory: httpd:2.4 security update
- csaf_redhat · RHSA-2024:5239Red Hat Security Advisory: Red Hat JBoss Core Services Apache HTTP Server 2.4.57 SP5 security update
- csaf_suse · SUSE-SU-2024:2436-1Security update for apache2
- csaf_redhat · RHSA-2024:4827Red Hat Security Advisory: httpd:2.4 security update
- csaf_redhat · RHSA-2024:4862Red Hat Security Advisory: httpd security update
- csaf_ncscnl · NCSC-2024-0464Kwetsbaarheden verholpen in SonicWall SMA100 SSLVPN
- csaf_redhat · RHSA-2024:4719Red Hat Security Advisory: httpd:2.4 security update
- csaf_redhat · RHSA-2024:4830Red Hat Security Advisory: httpd:2.4 security update
- csaf_ncscnl · NCSC-2024-0411Kwetsbaarheden verholpen in Oracle Database producten
- csaf_redhat · RHSA-2024:4943Red Hat Security Advisory: httpd security update
- csaf_ncscnl · NCSC-2025-0021Kwetsbaarheden verholpen in Oracle Communications
- csaf_redhat · RHSA-2024:4863Red Hat Security Advisory: httpd security update
- csaf_suse · SUSE-SU-2024:2624-1Security update for apache2
