ICS: Johnson Controls Kantech Door Controllers Vulnerability
July 4, 2024Millions of Phone Numbers Exposed Due to Twilio’s Authy App Breach
July 4, 2024ICS: Johnson Controls Kantech Door Controllers Vulnerability
July 4, 2024Millions of Phone Numbers Exposed Due to Twilio’s Authy App Breach
July 4, 2024Severity
Medium
Analysis Summary
CVE-2024-39884
Apache HTTP Server allow a remote attacker to obtain sensitive information, caused by a regression in the core related to ignoring some use of the legacy content-type based configuration of handlers. By using AddType, an attacker could exploit this vulnerability resulting in source code disclosure of local content.
Impact
- Information Disclosure
Indicators of Compromise
CVE
- CVE-2024-39884
Affected Vendors
Affected Products
- Apache HTTP Server 2.4.60
Remediation
Upgrade to the latest version of Apache HTTP Server, available from the Apache Website.