VYPR
Unrated severityNVD Advisory· Published Jul 18, 2024· Updated Sep 13, 2024

Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows

CVE-2024-40898

Description

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests.

Users are recommended to upgrade to version 2.4.62 which fixes this issue.

Affected products

3

Patches

1

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

1

News mentions

0

No linked articles in our index yet.