CVE-2024-38472

CVE-2024-38472: Apache HTTP Server on WIndows UNC SSRF

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-918 · SSRF
Published July 1, 2024
Last update November 18, 2024

CVSS base score

What the vulnerability does

Description

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.

Key dates

Disclosure timeline

July 1, 2024 CVE published
November 18, 2024 Record updated