SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 22, 2024 | Jul 1, 2024 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Oct 14, 2024 | Jul 1, 2024 |
| Debian | — | Upgrade apache2 | Jul 30, 2024 | Jul 30, 2024 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Sep 30, 2024 | Jul 1, 2024 |
| Ibm Http_server | — | Apply IBM HTTP Server Interim Fix PH61893Apply IBM HTTP Server version 9.0.5.21 or laterApply IBM HTTP Server version 8.5.5.27 or later | Nov 26, 2025 | Jul 29, 2024 |
| Suse | — | Upgrade apache2-manualUpgrade apache2Upgrade apache2-preforkUpgrade apache2-workerUpgrade apache2-develUpgrade apache2-utilsUpgrade apache2-event | Dec 5, 2025 | Dec 5, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 1, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub