PT-2024-4830 · Apache+2 · Apache Http Server+2
Orange Tsai
·
Published
2024-07-01
·
Updated
2025-08-12
·
CVE-2024-38472
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server versions prior to 2.4.60
Description:
The issue is related to Server-Side Request Forgery (SSRF) in the Apache HTTP Server on Windows, which can potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content. Existing configurations that access UNC paths will have to configure the new directive "UNCList" to allow access during request processing.
Recommendations:
To resolve the issue, users are recommended to upgrade to version 2.4.60, which fixes this problem.
Existing configurations that access UNC paths should configure the new directive "UNCList" to allow access during request processing.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Apache Http Server
Red Os