Improper escaping of output in mod_rewrite in Apache HTTP Server 2.4.59 and earlier allows an attacker to map URLs to filesystem locations that are permitted to be served by the server but are not intentionally/directly reachable by any URL, resulting in code execution or source code disclosure. Substitutions in server context that use a backreferences or variables as the first segment of the substitution are affected. Some unsafe RewiteRules will be broken by this change and the rewrite flag "UnsafePrefixStat" can be used to opt back in once ensuring the substitution is appropriately constrained.
We have discovered 1,328,741 live websites that are affected by CVE-2024-38475.
| Product | |
| Category | Web Servers |
| Vulnerable Domains | 1,328,741 live websites (48% of Apache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 51 versions ( 43% of all versions) |
| 399,606 websites | |
| 151,624 websites | |
| 79,441 websites | |
| 62,741 websites | |
| 48,904 websites | |
| 48,300 websites | |
| 46,493 websites | |
| 36,529 websites | |
| 36,117 websites | |
| 34,920 websites |
| .com | 484,575 websites |
| .de | 90,241 websites |
| .org | 64,567 websites |
| .net | 52,720 websites |
| .nl | 47,215 websites |
| .ru | 42,753 websites |
| .it | 41,347 websites |
| .cz | 29,091 websites |
| .fr | 26,275 websites |
| .pl | 25,745 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *******.com | *** | ||
| *************.***.****.****.************.net | *** | ||
| *********.net | *** | ||
| ***.****.us | *,*** | ||
| ***.*********.com | *,*** | ||
| *****.*******.com | *,*** | ||
| ******.net | *,*** | ||
| ******************.com | *,*** | ||
| ****.*********.net | *,*** | ||
| ****.com | *,*** |
FAQ