ELA-1332-1 apache2 security update

proxy authentication bypass

2025-02-27
Packageapache2
Version2.4.10-10+deb8u30 (jessie)
Related CVEs CVE-2024-38473


apache2 a popular webserver was affected by a vulnerability.

Encoding problem allows request URLs with incorrect encoding to be sent to backend services, potentially bypassing authentication via crafted requests.



For Debian 8 jessie, these problems have been fixed in version 2.4.10-10+deb8u30.

We recommend that you upgrade your apache2 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.