PT-2024-4844 · Apache+1 · Apache Http Server+1

Smi1E

+1

·

Published

2024-07-17

·

Updated

2026-01-22

·

CVE-2024-40898

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions prior to 2.4.62
Description: The issue is related to a Server-side Request Forgery (SSRF) vulnerability in the mod rewrite module of the Apache HTTP Server on Windows. This vulnerability can be exploited by a remote attacker to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. The problem is caused by insufficient validation of incoming requests.
Recommendations: For versions prior to 2.4.62, upgrade to version 2.4.62, which fixes this issue. As a temporary workaround, consider restricting access to the mod rewrite module to minimize the risk of exploitation.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2024-05368
BIT-APACHE-2024-40898
CVE-2024-40898
MGASA-2024-0272
OPENSUSE-SU-2024:14245-1

Affected Products

Apache Http Server
Red Os