important: Apache HTTP Server on WIndows UNC SSRF (CVE-2024-38472)
High
Vulnerability Details
I reported this vulnerability through the official Apache HTTP Server security email on April 1, 2024, and received a fix along with a CVE number on July 1, 2024. You can check detailed information from there:
> https://httpd.apache.org/security/vulnerabilities_24.html
## Impact
SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests or content
Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
Actions
View on HackerOneReport Stats
- Report ID: 2585385
- State: Closed
- Substate: resolved
- Upvotes: 36