Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-43394

 

Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-43394

Published: July 10, 2025 / Updated: July 10, 2025


Vulnerability identifier: #VU112732
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-43394
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input when handling UNC paths on Windows. A remote attacker can trick the application into initiating requests to arbitrary systems and potentially leak NTLM hashes to a malicious server via mod_rewrite or apache expressions that pass unvalidated request input.

Note, the vulnerability affects Windows installations only. 



Affected software

Apache HTTP Server
IBM HTTP Server
Gentoo Linux
EasyApache
WebSphere Remote Server
IBM Rational ClearCase
IBM Rational ClearQuest
Oracle HTTP Server
IBM Business Automation Workflow
IBM Tivoli Monitoring
IBM Tivoli Netcool Configuration Manager
DevOps Code ClearCase
www-servers/apache

How to mitigate CVE-2024-43394

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.64
EasyApache - update to 4 25-24
IBM HTTP Server - addressed in versions 8.5.5.29, 9.0.5.25
www-servers/apache - update to 2.4.68
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5

External References

Related Security Bulletins