CVE-2024-40898
published 2024-07-18CVE-2024-40898: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.54%
72.2th percentile
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | < 2.4.62 | 2.4.62 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.61 | — |
| debian | apache2 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5LOW
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-f6mg-hq7f-jw2j: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF
ghsa_unreviewed·2024-07-18
CVE-2024-40898 [CRITICAL] CWE-918 GHSA-f6mg-hq7f-jw2j: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
OSV
CVE-2024-40898: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF
osv·2024-07-18·CVSS 7.5
CVE-2024-40898 [HIGH] CVE-2024-40898: SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2024-40898
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-40898 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2024-40898
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) vulnerability
CVE: CVE-2024-40898
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Microsoft
CVE-2024-40898: NIST NVD Details: https://nvd
vendor_msrc·2024-09-10·CVSS 7.5
CVE-2024-40898 [HIGH] CVE-2024-40898: NIST NVD Details: https://nvd
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2024-40898
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Exploit Status: DOS:N/A
Remediation: httpd
Red Hat
httpd: SSRF in Apache HTTP Server on Windows via mod_rewrite in server/vhost context
vendor_redhat·2024-07-18·CVSS 7.5
CVE-2024-40898 [HIGH] CWE-918 httpd: SSRF in Apache HTTP Server on Windows via mod_rewrite in server/vhost context
httpd: SSRF in Apache HTTP Server on Windows via mod_rewrite in server/vhost context
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
A flaw was found in HTTPd on Windows systems. This issue potentially allows NTLM hashes to be leaked via mod_rewrite in server/vhost context to a malicious server via Server-side request forgery (SSRF) and malicious requests or content.
Statement: This flaw only affects HTTPd running on Windows systems. Therefore, the HTTPd package as shipped in Red Hat Enterprise Linux 6, 7, 8 and 9 is not affected by this vulnerability.
Mitigation: Mitigation for this issu
Debian
CVE-2024-40898: apache2 - SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, ...
vendor_debian·2024·CVSS 7.5
CVE-2024-40898 [HIGH] CVE-2024-40898: apache2 - SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, ...
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Apache
Apache httpd: CVE-2024-40898
vendor_apache·CVSS 7.5
CVE-2024-40898 [HIGH] Apache httpd: CVE-2024-40898
Apache httpd: CVE-2024-40898
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. Acknowledgements: finder: Smi1e (DBAPPSecurity Ltd.) finder: xiaojunjie (DBAPPSecurity Ltd.) Reported to security team 2024-07-12 fixed by r1919248 in 2.4.x 2024-07-15 Update 2.4.62 released 2024-07-17 Affects 2.4.0 through 2.4.61
Severity: high
Affected versions: 2.4.62
No detection rules found.
No public exploits indexed.
2024-07-18
Published