Medium severity6.3NVD Advisory· Published Apr 4, 2024· Updated Jun 17, 2026
CVE-2024-24795
CVE-2024-24795
Description
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack.
Users are recommended to upgrade to version 2.4.59, which fixes this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
66- osv-coords55 versionspkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Manager%20Proxy%204.3pkg:rpm/suse/apache2&distro=SUSE%20Manager%20Server%204.3pkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/apache2-manual&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/apache2-prefork&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/apache2-utils&distro=openSUSE%20Leap%2015.6pkg:rpm/almalinux/httpd-corepkg:rpm/almalinux/httpd-toolspkg:rpm/almalinux/mod_sessionpkg:rpm/almalinux/mod_sslpkg:bitnami/apachepkg:rpm/suse/uwsgi&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/uwsgi&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/opensuse/uwsgi&distro=openSUSE%20Leap%2015.5pkg:rpm/almalinux/httpdpkg:rpm/almalinux/httpd-develpkg:rpm/almalinux/httpd-filesystempkg:rpm/almalinux/httpd-manualpkg:rpm/almalinux/mod_ldappkg:rpm/almalinux/mod_luapkg:rpm/almalinux/mod_proxy_htmlpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/opensuse/uwsgi&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/apache2-tls13&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/apache2-tls13&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/apache2-tls13&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/apache2&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/apache2-worker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/opensuse/apache2-devel&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/apache2-event&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/apache2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/apache2-event&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/apache2-devel&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/suse/apache2-utils&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP6pkg:rpm/opensuse/apache2&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/apache2-worker&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/uwsgi&distro=openSUSE%20Tumbleweedpkg:rpm/suse/apache2-prefork&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6
< 2.4.51-150400.6.17.1+ 54 more
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 1:2.4.62-1.el9
- (no CPE)range: >= 2.4.0, < 2.4.59
- (no CPE)range: < 2.0.19.1-150400.8.3.1
- (no CPE)range: < 2.0.19.1-150400.8.3.1
- (no CPE)range: < 2.0.19.1-150400.8.3.1
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 2.4.62-1.el9
- (no CPE)range: < 1:2.4.62-1.el9
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.0.19.1-150400.8.3.1
- (no CPE)range: < 2.4.51-35.41.1
- (no CPE)range: < 2.4.51-35.41.1
- (no CPE)range: < 2.4.51-35.41.1
- (no CPE)range: < 2.4.51-35.41.1
- (no CPE)range: < 2.4.51-35.41.1
- (no CPE)range: < 2.4.51-35.41.1
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.51-150200.3.62.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.51-150400.6.17.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.4.58-150600.5.3.1
- (no CPE)range: < 2.0.28-1.1
- (no CPE)range: < 2.4.58-150600.5.3.1
<2.4.59+ 2 more
- (no CPE)range: <2.4.59
- (no CPE)range: 2.4.0
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: >=2.4.0,<2.4.59
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:ontap_tools:10:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:o:broadcom:fabric_operating_system:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
10- httpd.apache.org/security/vulnerabilities_24.htmlnvdRelease NotesVendor Advisory
- lists.debian.org/debian-lts-announce/2024/05/msg00013.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2024/05/msg00014.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/I2N2NZEX3MR64IWSGL3QGN7KSRUGAEMF/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/LX5U34KYGDYPRH3AJ6MDDCBJDWDPXNVJ/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/WNV4SZAPVS43DZWNFU7XBYYOZEZMI4ZC/nvdThird Party Advisory
- security.netapp.com/advisory/ntap-20240415-0013/nvdThird Party Advisory
- support.apple.com/kb/HT214119nvdThird Party Advisory
- seclists.org/fulldisclosure/2024/Jul/18nvdMailing List
- www.openwall.com/lists/oss-security/2024/04/04/5nvdMailing List
News mentions
0No linked articles in our index yet.