CVE-2024-40898
HIGH7.5EPSS 0.73%Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
Published: 7/18/2024Modified: 12/3/2025
Description
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Affected packages (2)
- Alpine/apache2from 0, < 2.4.62-r0
- Bitnami/apache>= 2.4.0, < 2.4.62
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |