Server-Side Request Forgery (SSRF) in Apache HTTP Server - CVE-2024-40898
Published: July 17, 2024 / Updated: November 15, 2024
Apache HTTP Server
IBM HTTP Server
Gentoo Linux
Slackware Linux
Anolis OS
Communications Unified Assurance
IBM Rational ClearQuest
Oracle Communications Cloud Native Core Automated Test Suite
IBM Tivoli Monitoring
IBM Rational Build Forge
EMC NetWorker Server
SecurityCenter
JBoss Core Services
www-servers/apache
httpd
httpd-doc
mod_ssl
mod_session
mod_proxy_html
mod_lua
mod_ldap
httpd-tools
httpd-devel
httpd-core
httpd-filesystem
httpd-manual
IBM Aspera Console
Maximo Application Suite - IoT Component
CTPView
NetWorker Management Console (NMC)
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to perform SSRF attacks.
The vulnerability exists due to insufficient validation of user-supplied input in Apache HTTP Server on Windows with mod_rewrite in server/vhost context. A remote attacker can force the web server to leak NTML hashes to a malicious server via SSRF and malicious requests.