Lucene search

K
ubuntucveUbuntu.comUB:CVE-2024-38472
HistoryJul 01, 2024 - 12:00 a.m.

CVE-2024-38472

2024-07-0100:00:00
ubuntu.com
ubuntu.com
ssrf
apache http server
windows
ntml hashes
upgrade
version 2.4.60
unc paths

6.8 Medium

AI Score

Confidence

Low

SSRF in Apache HTTP Server on Windows allows to potentially leak NTML
hashes to a malicious server via SSRF andΒ malicious requests or content
Users are recommended to upgrade to version 2.4.60 which fixes this issue.
Note: Existing configurations that access UNC paths will have to configure
new directive β€œUNCList” to allow access during request processing.

Notes

Author Note
alexmurray Only affects Apache HTTP Server on Windows so apache2 in Ubuntu is not affected.

6.8 Medium

AI Score

Confidence

Low