Bugzilla – Bug 1227267
VUL-0: CVE-2024-38472: apache2: UNC SSRF on WIndows
Last modified: 2024-07-17 12:41:11 UTC
SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing. References: https://httpd.apache.org/security/vulnerabilities_24.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-38472 https://seclists.org/oss-sec/2024/q3/4 https://www.cve.org/CVERecord?id=CVE-2024-38472
Windows only, closing