CVE-2024-38472 The advisory has been revoked - it doesn't affect any version of package apache2  (opens in a new tab)


Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
83.54% (100th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN11-APACHE2-7414094
  • published2 Jul 2024
  • disclosed1 Jul 2024

Introduced: 1 Jul 2024

CVE-2024-38472  (opens in a new tab)

Amendment

The Debian security team deemed this advisory irrelevant for Debian:11.

NVD Description

Note: Versions mentioned in the description apply only to the upstream apache2 package and not the apache2 package as distributed by Debian.

SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue.  Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.