CVE-2024-38472: Apache HTTP Server on WIndows UNC SSRF
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
Other sources
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content. Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38472?
CVE-2024-38472 has a high severity rating due to the potential for NTLM hash leakage.
How do I fix CVE-2024-38472?
To fix CVE-2024-38472, upgrade to Apache HTTP Server version 2.4.60 or later.
What does CVE-2024-38472 affect?
CVE-2024-38472 affects Apache HTTP Server on Windows.
What type of vulnerability is CVE-2024-38472?
CVE-2024-38472 is a Server-Side Request Forgery (SSRF) vulnerability.
Are existing configurations impacted by CVE-2024-38472?
Yes, existing configurations that access UNC paths may be impacted by CVE-2024-38472 after the upgrade.