#VU93542 Input validation error in Apache HTTP Server - CVE-2024-38475
Published: July 1, 2024 / Updated: May 1, 2025
Apache HTTP Server
Apache Foundation
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to insufficient validation of user-supplied input in mod_rewrite when first segment of substitution matches filesystem path. A remote attacker can map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL and view contents of files or execute arbitrary code.