Microsoft Security Response Center guidance
CBL-Mariner Releases
Vendor-listed releases
- 2.4.59-1
- 2.4.61-1
Vulnerability intelligence
CVE-2024-24795 and is rated Medium severity with a CVSS score of 6.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
CBL-Mariner Releases
HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended to upgrade to version 2.4.59, which fixes this issue.