Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-40898

 

Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-40898

Published: July 17, 2024 / Updated: November 15, 2024


Vulnerability identifier: #VU94503
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2024-40898
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform SSRF attacks.

The vulnerability exists due to insufficient validation of user-supplied input in Apache HTTP Server on Windows with mod_rewrite in server/vhost context. A remote attacker can force the web server to leak NTML hashes to a malicious server via SSRF and malicious requests.


Affected software

Apache HTTP Server
IBM HTTP Server
Gentoo Linux
Slackware Linux
Anolis OS
Communications Unified Assurance
IBM Rational ClearQuest
Oracle Communications Cloud Native Core Automated Test Suite
IBM Tivoli Monitoring
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
JBoss Core Services
www-servers/apache
httpd
httpd-doc
mod_ssl
mod_session
mod_proxy_html
mod_lua
mod_ldap
httpd-tools
httpd-devel
httpd-core
httpd-filesystem
httpd-manual
IBM Aspera Console
Maximo Application Suite - IoT Component
CTPView
NetWorker Management Console (NMC)

How to mitigate CVE-2024-40898

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.62
Communications Unified Assurance - update to 6.0.5
IBM HTTP Server - addressed in versions 8.5.5.27, 9.0.5.21
SecurityCenter - update to SC-202408.1
JBoss Core Services - update to 2.4.57 SP6
www-servers/apache - update to 2.4.62
httpd - update to 2.4.62
httpd-doc - update to 2.4.62-1
mod_ssl - update to 2.4.62-1
mod_session - update to 2.4.62-1
mod_proxy_html - update to 2.4.62-1
mod_lua - update to 2.4.62-1
mod_ldap - update to 2.4.62-1
httpd-tools - update to 2.4.62-1
httpd-devel - update to 2.4.62-1
httpd-core - update to 2.4.62-1
httpd - update to 2.4.62-1
httpd-filesystem - update to 2.4.62-1
httpd-manual - update to 2.4.62-1
IBM Aspera Console - update to 3.4.5
IBM Tivoli Monitoring - update to 6.3.0.7 Plus Service Pack 5
IBM Rational Build Forge - update to 8.0.0.27
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
CTPView - update to 9.2R1
EMC NetWorker Server - update to 19.10.0.5
NetWorker Management Console (NMC) - update to 19.10.0.5

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins