CVE-2024-38479
Last modified
CVE-2024-38479 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.. EPSS estimates a 0.94% chance of exploitation in the next 30 days.
Description
Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.5. Users are recommended to upgrade to version 9.2.6, which fixes the issue, or 10.0.2, which does not have the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Traffic Server | >= 8.0.0, <= 8.1.11 |
| Apache | Traffic Server | >= 9.0.0, < 9.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-38479?
How severe is CVE-2024-38479?
How do I fix CVE-2024-38479?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-38472SSRF in Apache HTTP Server on Windows allows to potentially …7.5
- CVE-2024-38473Encoding problem in mod_proxy in Apache HTTP Server 2.4.59 a…8.1
- CVE-2024-38474Substitution encoding issue in mod_rewrite in Apache HTTP Se…9.8
- CVE-2024-38475Improper escaping of output in mod_rewrite in Apache HTTP Se…9.1
- CVE-2024-38476Vulnerability in core of Apache HTTP Server 2.4.59 and earli…9.8
- CVE-2024-38477null pointer dereference in mod_proxy in Apache HTTP Server …7.5
- CVE-2024-3848A path traversal vulnerability exists in mlflow/mlflow versi…7.5
- CVE-2024-38480"Piccoma" App for Android and iOS versions prior to 6.20.0 u…4
- CVE-2024-38481Dell iDRAC Service Module version 5.3.0.0 and prior, contain…4.4
- CVE-2024-38482CloudLink, versions 7.1.x and 8.x, contain an Improper check…7.2
- CVE-2024-38483Dell BIOS contains an Improper Input Validation vulnerabilit…6.7
- CVE-2024-38485Dell ECS, versions prior to 3.8.0, contain(s) a Host Header …4.3
Are you affected by CVE-2024-38479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
