Vulnerabilities > Apache > Http Server > 2.4.60

DATE CVE VULNERABILITY TITLE RISK
2024-07-18 CVE-2024-40725 Unspecified vulnerability in Apache Http Server 2.4.60/2.4.61
A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handlers.
network
low complexity
apache
5.3
2024-07-18 CVE-2024-40898 Unspecified vulnerability in Apache Http Server
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 
network
low complexity
apache
7.5
2024-07-01 CVE-2024-38476 Vulnerability in core of Apache HTTP Server 2.4.59 and earlier are vulnerably to information disclosure, SSRF or local script execution via backend applications whose response headers are malicious or exploitable. Users are recommended to upgrade to version 2.4.60, which fixes this issue.
network
low complexity
apache netapp
critical
9.8