SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.
Users are recommended to upgrade to version 2.4.62 which fixes this issue.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade apache2 | Aug 22, 2024 | Jul 18, 2024 |
| Apache Httpd | — | Upgrade to the latest version of Apache HTTPD | Oct 14, 2024 | Jul 18, 2024 |
| Gentoo Linux | — | Upgrade www-servers/apache. | Sep 30, 2024 | Jul 18, 2024 |
| Ibm Http_server | — | Apply IBM HTTP Server version 8.5.5.27 or laterApply IBM HTTP Server Interim Fix PH62263Apply IBM HTTP Server version 9.0.5.21 or later | Nov 26, 2025 | Jul 29, 2024 |
| Suse | — | Upgrade apache2-manualUpgrade apache2-develUpgrade apache2Upgrade apache2-preforkUpgrade apache2-utilsUpgrade apache2-workerUpgrade apache2-event | Dec 5, 2025 | Dec 5, 2025 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Jul 18, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub