We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-40725

Apache HTTP Server: source code disclosure with handlers configured via AddType



Assignerapache
Reserved2024-07-09
Published2024-07-18
Updated2024-08-08

Description

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted. Users are recommended to upgrade to version 2.4.62, which fixes this issue.

Problem types

CWE-668 Exposure of Resource to Wrong Sphere

Product status

Default status
unaffected

2.4.60
affected

Timeline

2024-07-09:reported

References

https://httpd.apache.org/security/vulnerabilities_24.html vendor-advisory

cve.org CVE-2024-40725

nvd.nist.gov CVE-2024-40725

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.