Apache HTTPD Unsafe URL with %3f (CVE-2024-38474)

Solution Verified - Updated -

Issue

  • Getting Forbidden error for URL after OS patching.

    [Sun Aug 18 08:09:03.832147 2024] [rewrite:error] [pid 999999:tid 999999999999999] [client 999.999.999.999:99999] AH: Unsafe URL with %3f URL rewritten without UnsafeAllow3F, referer: https://hostname/path/cgi-bin/script.cgi
    

Environment

  • Red Hat Enterprise Linux (RHEL)
  • Apache Web Server (HTTPD)
    • JBoss Core Services (JBCS) httpd 2.4.57 SP5+

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content