PT-2025-29115 · Apache+2 · Apache Http Server+2

Published

2025-07-10

·

Updated

2025-12-26

·

CVE-2024-43394

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions 2.4.0 through 2.4.63
Description: A Server-Side Request Forgery (SSRF) issue exists in Apache HTTP Server on Windows. This issue potentially allows the leakage of NTLM hashes to a malicious server via mod rewrite or Apache expressions that process unvalidated request input. The server offers limited protection against administrators directing it to open UNC paths. Windows servers should limit the hosts they will connect to over SMB based on the nature of NTLM authentication.
Recommendations: Update to a version later than 2.4.63.

Fix

SSRF

Weakness Enumeration

Related Identifiers

BDU:2025-08951
BIT-APACHE-2024-43394
CVE-2024-43394
DLA-4270-1
OPENSUSE-SU-2025:15360-1

Affected Products

Apache Http Server
Red Os
Windows