Vulnerabilities > CVE-2024-40898 - Server-Side Request Forgery (SSRF) vulnerability in Apache Http Server

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
apache
CWE-918

Summary

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

Vulnerable Configurations

Part Description Count
Application
Apache
264
OS
Microsoft
1

Common Weakness Enumeration (CWE)