CVE-2024-43394: Apache HTTP Server: SSRF on Windows due to UNC paths
Server-Side Request Forgery (SSRF) in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via modrewrite or apache expressions that pass unvalidated request input.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.63.
Note: The Apache HTTP Server Project will be setting a higher bar for accepting vulnerability reports regarding SSRF via UNC paths.
The server offers limited protection against administrators directing the server to open UNC paths. Windows servers should limit the hosts they will connect over via SMB based on the nature of NTLM authentication.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-43394?
CVE-2024-43394 is classified as a medium-severity vulnerability due to its potential to leak sensitive information.
How do I fix CVE-2024-43394?
To fix CVE-2024-43394, users should upgrade their Apache HTTP Server to version 2.4.64 or later.
What is the impact of CVE-2024-43394?
CVE-2024-43394 can allow an attacker to exploit Server-Side Request Forgery to leak NTLM hashes to a malicious server.
Which versions of Apache HTTP Server are affected by CVE-2024-43394?
CVE-2024-43394 affects Apache HTTP Server versions from 2.4.0 to 2.4.63.
Is CVE-2024-43394 a common vulnerability?
CVE-2024-43394 is considered a common vulnerability due to the widespread use of Apache HTTP Server and the potential impact of SSRF.