Rewterz
ICS: Johnson Controls Kantech Door Controllers Vulnerability
July 4, 2024
Rewterz
Millions of Phone Numbers Exposed Due to Twilio’s Authy App Breach
July 4, 2024

CVE-2024-39884 – Apache HTTP Server Vulnerability

Severity

Medium

Analysis Summary

CVE-2024-39884

Apache HTTP Server allow a remote attacker to obtain sensitive information, caused by a regression in the core related to ignoring some use of the legacy content-type based configuration of handlers. By using AddType, an attacker could exploit this vulnerability resulting in source code disclosure of local content.

Impact

  • Information Disclosure

Indicators of Compromise

CVE

  • CVE-2024-39884

Affected Vendors

Apache

Affected Products

  • Apache HTTP Server 2.4.60

Remediation

Upgrade to the latest version of Apache HTTP Server, available from the Apache Website.

Apache Website