CVE-2024-43204
10.07.2025, 17:15
SSRF in Apache HTTP Server with mod_proxy loaded allows an attacker to send outbound proxy requests to a URL controlled by the attacker. Requires an unlikely configuration where mod_headers is configured to modify the Content-Type request or response header with a value provided in the HTTP request. Users are recommended to upgrade to version 2.4.64 which fixes this issue.
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.0 ≤ 𝑥 < 2.4.64 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Vulnerability Media Exposure