CVE-2024-38472 Details
Description
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
A Server-Side Request Forgery (SSRF) vulnerability has been identified in Apache HTTP Server on Windows, allowing the potential leakage of NTLM hashes to a malicious server. This issue arises when the server is configured to access UNC paths, with 'AllowEncodedSlashes' enabled and 'MergeSlashes' disabled. The vulnerability can be exploited through crafted requests or content that takes advantage of the server's SSRF handling.
Users are advised to upgrade to Apache HTTP Server version 2.4.60 or later, which addresses this vulnerability. After upgrading, review and adjust any configurations that access UNC paths to include the new 'UNCList' directive, allowing proper access during request processing.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 25, 2024References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://httpd.apache.org/security/vulnerabilities_24.html | CVE | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20240712-0001/ | CVE | Third Party Advisory |
| http://www.openwall.com/lists/oss-security/2024/07/01/5 | CVE | Mailing List |
| https://httpd.apache.org/security/vulnerabilities_24.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache http server | >= 2.4.0, < 2.4.60 |
CPE
Remediation
| |
| netapp ontap | 9 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jul 1, 2025 | Initial Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Nov 18, 2024 | CVE Modified | [email protected] |
| Jul 12, 2024 | CVE Modified | [email protected] |
| Jul 9, 2024 | CVE Modified | CISA-ADP |
| Jul 1, 2024 | New CVE Received | [email protected] |