Potential SSRF in mod_rewrite in Apache HTTP Server 2.4...
High severity
Unreviewed
Published
Jul 1, 2024
to the GitHub Advisory Database
•
Updated Jul 12, 2024
Description
Published by the National Vulnerability Database
Jul 1, 2024
Published to the GitHub Advisory Database
Jul 1, 2024
Last updated
Jul 12, 2024
Potential SSRF in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to cause unsafe RewriteRules to unexpectedly setup URL's to be handled by mod_proxy.
Users are recommended to upgrade to version 2.4.60, which fixes this issue.
References