Lucene search

K
vulnrichmentApacheVULNRICHMENT:CVE-2024-38472
HistoryJul 01, 2024 - 6:12 p.m.

CVE-2024-38472 Apache HTTP Server on WIndows UNC SSRF

2024-07-0118:12:27
CWE-918
apache
github.com
17
apache
http server
windows
ssrf
vulnerability
fix
unc
ssrf
ntml
hashes
upgrade
version 2.4.60
configuration
unclist
access
directive

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

20.2%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial

SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF andΒ malicious requests or content
Users are recommended to upgrade to version 2.4.60 which fixes this issue.Β  Note: Existing configurations that access UNC paths will have to configure new directive β€œUNCList” to allow access during request processing.

ADP Affected

[
  {
    "cpes": [
      "cpe:2.3:a:apache_software_foundation:apache_http_server:*:*:*:*:*:*:*:*"
    ],
    "vendor": "apache_software_foundation",
    "product": "apache_http_server",
    "versions": [
      {
        "status": "affected",
        "version": "0",
        "lessThan": "2.4.60",
        "versionType": "custom"
      }
    ],
    "defaultStatus": "unknown"
  }
]

AI Score

6.3

Confidence

Low

EPSS

0.001

Percentile

20.2%

SSVC

Exploitation

none

Automatable

yes

Technical Impact

partial