PT-2024-4844 · Apache+1 · Apache Http Server+1
Smi1E
+1
·
Published
2024-07-17
·
Updated
2026-01-22
·
CVE-2024-40898
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Apache HTTP Server versions prior to 2.4.62
Description:
The issue is related to a Server-side Request Forgery (SSRF) vulnerability in the mod rewrite module of the Apache HTTP Server on Windows. This vulnerability can be exploited by a remote attacker to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. The problem is caused by insufficient validation of incoming requests.
Recommendations:
For versions prior to 2.4.62, upgrade to version 2.4.62, which fixes this issue.
As a temporary workaround, consider restricting access to the mod rewrite module to minimize the risk of exploitation.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Apache Http Server
Red Os