This is one of the most famous exploits for the 2.4.17 to 2.4.38 range.
: If certain modules like mod_ldap or mod_authnz_ldap are not needed, consider disabling them to reduce the attack surface.
: A single remote, unauthenticated attacker can exhaust the server's thread pool, causing the application to stop responding to legitimate users. 3. Path Traversal and RCE (CVE-2021-41773 & CVE-2024-38475)
The impact of this vulnerability is severe: