Apache HTTPD Unsafe URL with %3f (CVE-2024-38474)
Issue
-
Getting Forbidden error for URL after OS patching.
[Sun Aug 18 08:09:03.832147 2024] [rewrite:error] [pid 999999:tid 999999999999999] [client 999.999.999.999:99999] AH: Unsafe URL with %3f URL rewritten without UnsafeAllow3F, referer: https://hostname/path/cgi-bin/script.cgi
Environment
- Red Hat Enterprise Linux (RHEL)
- Apache Web Server (HTTPD)
- JBoss Core Services (JBCS) httpd 2.4.57 SP5+
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.