Lucene search

K
osvGoogleOSV:BIT-APACHE-2024-38472
HistoryJul 03, 2024 - 7:17 a.m.

BIT-apache-2024-38472

2024-07-0307:17:47
Google
osv.dev
3
ssrf
apache http server
windows
ntml hashes
malicious requests
upgrade
unc paths
unclist

6.7 Medium

AI Score

Confidence

Low

SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF andΒ malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.Β  Note: Existing configurations that access UNC paths will have to configure new directive β€œUNCList” to allow access during request processing.

CPENameOperatorVersion
apachelt2.4.60
apachege2.4.0

6.7 Medium

AI Score

Confidence

Low