SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Sep 2024 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat jboss Core Services |
|
| CPEs | cpe:/a:redhat:jboss_core_services:1 | |
| Vendors & Products |
Redhat
Redhat jboss Core Services |
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 08 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache http Server Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apache
Apache http Server Microsoft Microsoft windows |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 08 Aug 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:05:09.541Z
Reserved: 2024-07-12T11:46:13.929Z
Link: CVE-2024-40898
Updated: 2024-09-13T17:05:09.541Z
Status : Modified
Published: 2024-07-18T10:15:03.217
Modified: 2024-11-21T09:31:48.670
Link: CVE-2024-40898
OpenCVE Enrichment
No data.