Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-40898

Опубликовано: 18 июл. 2024
Источник: debian
EPSS Низкий

Описание

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2not-affectedpackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2024-40898

  • Fixed by https://github.com/apache/httpd/commit/9967bf49599f9be6eaaf9c5de5c84f15bb07df9f

EPSS

Процентиль: 26%
0.00088
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.

CVSS3: 7.5
redhat
около 1 года назад

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

CVSS3: 7.5
nvd
около 1 года назад

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

CVSS3: 7.5
msrc
около 1 года назад

Описание отсутствует

CVSS3: 9.1
github
около 1 года назад

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

EPSS

Процентиль: 26%
0.00088
Низкий