Apache2: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers.
A partial fix for CVE-2024-39884 in Apache HTTP Server 2.4.61 fails to fully address the issue with legacy content-type based handler configurations such as "AddType". Under certain conditions, this can cause source code disclosure of local content, for example serving PHP scripts as plain text instead of interpreting them. The issue is fixed in Apache HTTP Server version 2.4.62. Users are advised to upgrade to this version to resolve the vulnerability.
AI Analysis
Technical Summary
The vulnerability involves incomplete remediation of CVE-2024-39884 in Apache HTTP Server 2.4.61, where legacy content-type based configuration directives like "AddType" can cause source code disclosure when files are requested indirectly. This means that instead of executing scripts such as PHP, the server may serve the raw source code to clients. The issue affects multiple Ubuntu-packaged versions of Apache HTTP Server prior to 2.4.62. Upgrading to version 2.4.62 addresses this vulnerability.
Potential Impact
The vulnerability can lead to local source code disclosure, exposing potentially sensitive information contained within server-side scripts. This exposure does not affect integrity or availability but compromises confidentiality by revealing source code that should remain private.
Mitigation Recommendations
An official fix is available in Apache HTTP Server version 2.4.62. Users should upgrade to this version to fully remediate the vulnerability. Until upgraded, the partial fix in 2.4.61 does not fully prevent source code disclosure when using legacy content-type based handler configurations.
Apache2: A partial fix for CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers.
Description
A partial fix for CVE-2024-39884 in Apache HTTP Server 2.4.61 fails to fully address the issue with legacy content-type based handler configurations such as "AddType". Under certain conditions, this can cause source code disclosure of local content, for example serving PHP scripts as plain text instead of interpreting them. The issue is fixed in Apache HTTP Server version 2.4.62. Users are advised to upgrade to this version to resolve the vulnerability.
CVSS v3.1
Affected software
pkg:deb/ubuntu/[email protected]+esm15?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]?arch=source&distro=focalpkg:deb/ubuntu/[email protected]?arch=source&distro=jammypkg:deb/ubuntu/[email protected]?arch=source&distro=nobleRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves incomplete remediation of CVE-2024-39884 in Apache HTTP Server 2.4.61, where legacy content-type based configuration directives like "AddType" can cause source code disclosure when files are requested indirectly. This means that instead of executing scripts such as PHP, the server may serve the raw source code to clients. The issue affects multiple Ubuntu-packaged versions of Apache HTTP Server prior to 2.4.62. Upgrading to version 2.4.62 addresses this vulnerability.
Potential Impact
The vulnerability can lead to local source code disclosure, exposing potentially sensitive information contained within server-side scripts. This exposure does not affect integrity or availability but compromises confidentiality by revealing source code that should remain private.
Mitigation Recommendations
An official fix is available in Apache HTTP Server version 2.4.62. Users should upgrade to this version to fully remediate the vulnerability. Until upgraded, the partial fix in 2.4.61 does not fully prevent source code disclosure when using legacy content-type based handler configurations.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2024-40725
- Osv Schema Version
- 1.7.0
- Aliases
- []
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS"]
- Database Specific Severity
- null
- Cvss Version
- 3.1
Threat ID: 6a6151299c2644c7f8da6db8
Added to database: 07/22/2026, 23:24:25 UTC
Last enriched: 07/23/2026, 00:23:18 UTC
Last updated: 07/27/2026, 11:08:47 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.