CVE-2024-43204

HIGH7.5EPSS 0.70%

Apache HTTP Server: SSRF with mod_headers setting Content-Type header

發布日:2025/7/10修改日:2025/11/6
也稱為:ALPINE-CVE-2024-43204BIT-apache-2024-43204DEBIAN-CVE-2024-43204

描述

SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker.  Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are recommended to upgrade to version 2.4.64 which fixes this issue.

受影響套件(3)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

參考連結(7)