Is VMware Smarts Assurance NCM vulnerable to CVE-2024-38475?
search cancel

Is VMware Smarts Assurance NCM vulnerable to CVE-2024-38475?

book

Article ID: 396981

calendar_today

Updated On:

Products

VMware Smart Assurance

Issue/Introduction

We would like to know if the NCM component of VMware Smarts Assurance is vulnerable to the HTTPD CVE-2024-38475?

Environment

VMware Smarts Assurance

NCM

Cause

As per Engineering this vulnerability is only present when using ReWriteRule in HTTPD with back references. 

Ex :: RewriteRule ^product/(\d+)$ /item/$1 [R=301,L]

In the example above, "$1" represents a back reference.

Since back references are not used by NCM httpd's RewriteRule, NCM is not impacted by this vulnerability.

Resolution

VMware Smarts Assurance NCM is not vulnerable to CVE-2024-38475, therefore no further action is needed.

Additional Information

In the upcoming release of VMware Smarts Assurance NCM 24.3.9 we will support up to Linux 9.5 that includes HTTPD 2.4.53 as the default.