important: Apache HTTP Server on WIndows UNC SSRF (CVE-2024-38472)

Disclosed: 2024-07-13 14:36:40 By orange To ibb
High
Vulnerability Details
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there: > https://httpd.apache.org/security/vulnerabilities_24.html ## Impact SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
Actions
View on HackerOne
Report Stats
  • Report ID: 2585385
  • State: Closed
  • Substate: resolved
  • Upvotes: 36
Share this report