First published: Thu Jul 18 2024(Updated: )
SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Http Server | <=2.4.61 | |
Apache Http Server |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
REDHAT-BUG-2298648 has a high severity due to its potential to leak NTLM hashes via SSRF.
To fix REDHAT-BUG-2298648, upgrade to Apache HTTP Server version 2.4.62 or later.
REDHAT-BUG-2298648 is a Server-Side Request Forgery (SSRF) vulnerability.
Apache HTTP Server versions up to and including 2.4.61 are affected by REDHAT-BUG-2298648.
An attacker can potentially access sensitive NTLM hashes from vulnerable servers using REDHAT-BUG-2298648.