SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Metrics
Affected Vendors & Products
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 24 Sep 2024 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat jboss Core Services |
|
CPEs | cpe:/a:redhat:jboss_core_services:1 | |
Vendors & Products |
Redhat
Redhat jboss Core Services |
Fri, 13 Sep 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 08 Aug 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache http Server Microsoft Microsoft windows |
|
CPEs | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
Vendors & Products |
Apache
Apache http Server Microsoft Microsoft windows |
|
Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 08 Aug 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:05:09.541Z
Reserved: 2024-07-12T11:46:13.929Z
Link: CVE-2024-40898

Updated: 2024-09-13T17:05:09.541Z

Status : Modified
Published: 2024-07-18T10:15:03.217
Modified: 2024-11-21T09:31:48.670
Link: CVE-2024-40898


No data.