HTTP: Apache httpd mod_cgi Handler Confusion

This signature detects attempts to exploit a known vulnerability against Apache. A successful attack can lead to arbitrary code execution

Extended Description

Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution viabackend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.

Affected Products

Apache http_server

Short Name
HTTP:APACHE:MOD-CGI-CONFUSION
Severity
Major
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Apache CVE-2024-38476 Confusion Handler httpd mod_cgi
Release Date
10/10/2024
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Apache

Netapp

Found a potential security threat?