The Apache Software Foundation has found multiple security issues in the widely used Apache HTTP Server. These vulnerabilities could lead to denial-of-service attacks, remote code execution, and unauthorized access, putting many websites at risk of cyberattacks.
CVE-2024-36387 to CVE-2024-39573 are vulnerabilities in Apache HTTP Server’s components like mod_proxy, mod_rewrite, and core functionalities. Some of the most serious issues are:
By infosecbulletin
/ Thursday , July 4 2024
Cybersecurity experts found 28 new types of ransomware in June. These malicious programs are a big threat to individuals and...
Read More
By infosecbulletin
/ Wednesday , July 3 2024
ISACA Dhaka Chapter election is going to be held on Saturday (6 July) 2024. This year 23 candidates will fight...
Read More
By infosecbulletin
/ Wednesday , July 3 2024
Google launched a new bug bounty program called kvmCTF to enhance the security of its Kernel-based Virtual Machine (KVM) hypervisor....
Read More
By infosecbulletin
/ Tuesday , July 2 2024
The Brain Cipher ransomware group to release the decryption keys for Indonesia Terkoneksi on Wednesday. They said their attack aims...
Read More
By infosecbulletin
/ Tuesday , July 2 2024
"A critical vulnerability has been identified in the Google Authentication mechanism of the application. By manipulating the ID and email...
Read More
By infosecbulletin
/ Tuesday , July 2 2024
The Apache Software Foundation has found multiple security issues in the widely used Apache HTTP Server. These vulnerabilities could lead...
Read More
By infosecbulletin
/ Tuesday , July 2 2024
An executive from National Australia Bank reveals that the four major banks in the country face continuous attacks, as threat...
Read More
By infosecbulletin
/ Monday , July 1 2024
There is a security flaw (CVE-2024-20399) in Cisco NX-OS Software that lets an attacker with local access execute commands as...
Read More
By infosecbulletin
/ Monday , July 1 2024
Despite the limited manpower and various limitations, efforts are being made to keep the country's cyber space safe, said the...
Read More
By infosecbulletin
/ Sunday , June 30 2024
Microsoft will assign Common Vulnerabilities and Exposures (CVE) numbers to important vulnerabilities found and fixed in their cloud services. This...
Read More
CVE-2024-38472 (Important): Server-Side Request Forgery (SSRF) vulnerability on Windows systems, potentially leaking sensitive NTML hashes.
CVE-2024-38474 (Important): Code execution and source disclosure via encoded question marks in backreferences.
CVE-2024-38475 (Important): Unauthorized access to filesystem locations through improper escaping in mod_rewrite.
CVE-2024-38476 (Important): Information disclosure, SSRF, or local script execution via malicious backend application output.
These vulnerabilities could let attackers crash servers, bypass authentication, steal sensitive data, or take control of affected systems. Upgrade to Apache Software Foundation version 2.4.60 to fix reported vulnerabilities. Organizations that don’t update their software on time may suffer from website crashes, data leaks, and money losses.
Additionally, organizations should:
Check and adjust settings, especially for mod_proxy and mod_rewrite, to prevent issues. Keep an eye on logs for any unusual activity or unauthorized access attempts. Consider using a web application firewall (WAF) to filter out harmful traffic and reduce the risk of attacks.