- Description
- SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue.
- Source
- security@apache.org
- NVD status
- Analyzed
- Products
- http_server
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- security@apache.org
- CWE-918
- Hype score
- Not currently trending
217.153.162.211 Fałszowanie żądań po stronie serwera (SSRF) CVE-2024-40898 Miasto Pruszków Kod pocztowy 05-800 Wydawca certyfikatu WYDANE SAMODZIELNIE https://t.co/LTMLDfM4m3 https://t.co/WdIZmP8eEv https://t.co/Ck7IGR6wsB https://t.co/FtfNN7s7aN
@KulinskiArkadi
29 Aug 2025
103 Impressions
1 Retweet
2 Likes
0 Bookmarks
1 Reply
0 Quotes
ip 217.153.162.211 City Pruszków Postal Code 05-800 Poland CVE-2024-40898 CVE-2024-36387 https://t.co/LTMLDfM4m3 https://t.co/wt97X1wdXk
@KulinskiArkadi
29 Aug 2025
78 Impressions
1 Retweet
1 Like
0 Bookmarks
1 Reply
0 Quotes
🚨 New PoC scanner released for CVE-2024-40898 – Apache HTTPD SSL cert validation bypass. 🧪 Multi-threaded ⚡ Fast, customizable 📜 CLI support 🔍 Detects weak TLS cert validation Test your perimeter now 👇 https://t.co/MC74sYb2lZ #infosec #CVE #cybersecurity #pe
@illdeed
7 Jul 2025
82 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
Arcserve UDP に同梱される、Apache HTTP Server の脆弱性 (CVE-2024-40898/CVE-2024-40725) 対応パッチが公開されました。Arcserve UDP 9.2 以前をご利用の方は適用をご検討ください。 P00003206 | Arcserve UDP 9.x | Patch for Apache httpd Vulnerabilities https://t.co/4EtoSZvbqW
@Arcserve_jp
19 Jan 2025
71 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*",
"matchCriteriaId": "305E43F5-3253-4B7B-A8B0-E6F937986C55",
"versionEndExcluding": "2.4.62",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
"matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]