High severity7.5NVD Advisory· Published Jul 1, 2024· Updated Jun 17, 2026
CVE-2024-38472
CVE-2024-38472
Description
SSRF in Apache HTTP Server on Windows allows to potentially leak NTLM hashes to a malicious server via SSRF and malicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive "UNCList" to allow access during request processing.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<2.4.60+ 2 more
- (no CPE)range: <2.4.60
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*range: >=2.4.0,<2.4.60
- (no CPE)range: 2.4.0
- osv-coords2 versions
< 2.4.61-1.1+ 1 more
- (no CPE)range: < 2.4.61-1.1
- (no CPE)range: >= 2.4.0, < 2.4.60
Patches
Vulnerability mechanics
References
3- httpd.apache.org/security/vulnerabilities_24.htmlnvdVendor Advisory
- security.netapp.com/advisory/ntap-20240712-0001/nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2024/07/01/5nvdMailing List
News mentions
0No linked articles in our index yet.