PT-2024-4844 · Apache+1 · Apache Http Server+1

·

CVE-2024-40898

·

Published

2024-07-17

·

Updated

2026-01-22

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions prior to 2.4.62
Description: The issue is related to a Server-side Request Forgery (SSRF) vulnerability in the mod rewrite module of the Apache HTTP Server on Windows. This vulnerability can be exploited by a remote attacker to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. The problem is caused by insufficient validation of incoming requests.
Recommendations: For versions prior to 2.4.62, upgrade to version 2.4.62, which fixes this issue. As a temporary workaround, consider restricting access to the mod rewrite module to minimize the risk of exploitation.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-05368
BIT-APACHE-2024-40898
CVE-2024-40898
MGASA-2024-0272
OPENSUSE-SU-2024:14245-1

Affected Products

Apache Http Server
Red Os