Loading HuntDB...

GHSA-x749-289q-pg9q

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers. "AddType" and similar configuration, under some circumstances where files are requested indirectly, result in source code disclosure of local content. For example, PHP scripts may be served instead of interpreted.

Users are recommended to upgrade to version 2.4.62, which fixes this issue.

Related CVEs

Key Information

GHSA ID
GHSA-x749-289q-pg9q
Published
July 18, 2024 12:30 PM
Last Modified
March 14, 2025 6:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.