Lucene search

K
redhatcveRedhat.comRH:CVE-2024-38472
HistoryJul 18, 2024 - 10:07 p.m.

CVE-2024-38472

2024-07-1822:07:24
redhat.com
access.redhat.com
35
cve-2024-38472
ssrf
apache http server
windows
ntml hashes
malicious requests
upgrade
version 2.4.60
unc paths
unclist

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

20.2%

A flaw was found in httpd on Windows systems. This issue potentially allows NTLM hashes to be leaked to a malicious server via Server-side request forgery (SSRF) and malicious requests or content.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

20.2%