Severity: important

Affected versions:

- Apache HTTP Server 2.4.60

Description:

A regression in the core of Apache HTTP Server 2.4.60 ignores some use of the 
legacy content-type based configuration of handlers.   "AddType" and similar 
configuration, under some circumstances where files are requested indirectly, 
result in source code disclosure of local content. For example, PHP scripts may 
be served instead of interpreted.

Users are recommended to upgrade to version 2.4.61, which fixes this issue.

References:

https://httpd.apache.org/security/vulnerabilities_24.html
https://httpd.apache.org/
https://www.cve.org/CVERecord?id=CVE-2024-39884

Timeline:

2024-07-01: reported

Reply via email to