Lucene search

K
alpinelinuxAlpine Linux Development TeamALPINE:CVE-2024-38472
HistoryJul 01, 2024 - 7:15 p.m.

CVE-2024-38472

2024-07-0119:15:04
Alpine Linux Development Team
security.alpinelinux.org
1
ssrf vulnerability
apache http server
ntml hash leak
upgrade
unc paths
windows

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%

SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF andΒ malicious requests or content
Users are recommended to upgrade to version 2.4.60 which fixes this issue.Β  Note: Existing configurations that access UNC paths will have to configure new directive β€œUNCList” to allow access during request processing.

7 High

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

9.2%