S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-38473 Scanner

CVE-2024-38473 Scanner - Improper Access Control vulnerability in Apache HTTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.2k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
31
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-38473
8.1
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient.

Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 and earlier allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Attack Vector
Network
Privileges Req.
Low
User Interaction
None
Affected
Apache HTTP Serverby Apache Software Foundation
2.4.0
apache_http_serverby apache_software_foundation
2.4.0
Updated Aug 22, 2026View on NVD →
Detail

Apache HTTP Server is a widely used web server software developed by the Apache Software Foundation. It is instrumental in serving HTTP requests on the internet, powering a significant portion of web servers globally. Its modular architecture allows extensions ranging from authentication modules to proxy services. Developers and system administrators across various sectors frequently utilize Apache HTTP Server for its robust features and adaptability. This software is particularly common in environments requiring high availability and performance, making it essential for businesses of all sizes. However, its exposure to the public internet and widespread use make it a frequent target for security vulnerabilities.

The ACL Bypass vulnerability in Apache HTTP Server stems from an encoding problem in mod_proxy. This vulnerability allows request URLs with incorrect encoding to be sent to backend services. The consequence of exploiting this flaw is the potential bypass of authentication, allowing unauthorized access to restricted areas. The issue, identified in versions 2.4.59 and earlier, poses a risk as attackers can craft requests to exploit the server's handling of improperly encoded URLs. This vulnerability is critical as it undermines the security mechanisms in place to protect access to sensitive services.

Technical details of this vulnerability highlight a flaw in the request URL encoding process handled by mod_proxy. Attackers can craft specific requests that, due to improper encoding handling, are forwarded to back-end services despite ACLs. This bypass allows unauthorized access without the proper authentication credentials. Vulnerable parameters include crucial paths like admin.php or environment configuration files that should typically be protected

If malicious users exploit this ACL Bypass vulnerability, it can lead to unauthorized access to sensitive information and administrative functions. Potential consequences include data leakage, modification of server configurations, and even the installation of malicious payloads on the server. This could compromise the integrity, confidentiality, and availability of the server and its hosted applications. The exposure of internal services due to flawed access controls could further aid attackers in lateral movement within a network, escalating the impact of this vulnerability.

REFERENCES

Solution Advice
  • Update Apache HTTP Server to version 2.4.60 or later, where the vulnerability has been fixed.
  • Implement strict access controls and regularly update ACLs to prevent unauthorized access.
  • Monitor server logs for any unusual or unauthorized access attempts that exploit URL encoding.
  • Use web application firewalls (WAFs) to detect and block potentially malicious requests.
  • Conduct regular vulnerability assessments to identify and mitigate similar risks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.