CVE-2024-40898

HIGH

Apache HTTP Server <2.4.62 - SSRF

Title source: llm

Description

SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF and malicious requests. Users are recommended to upgrade to version 2.4.62 which fixes this issue. 

Exploits (3)

github SCANNER 83 stars
by TAM-K592 · pythonpoc
https://github.com/TAM-K592/CVE-2024-40725-CVE-2024-40898
nomisec SCANNER 2 stars
by ForceEA001 · poc
https://github.com/ForceEA001/CVE-2024-40898-SSL-Bypass-Detection
nomisec SCANNER 1 stars
by anilpatel199n · poc
https://github.com/anilpatel199n/CVE-2024-40898

Scores

CVSS v3 7.5
EPSS 0.0047
EPSS Percentile 64.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-918
Status published

Affected Products (1)

apache/http_server < 2.4.62

Timeline

Published Jul 18, 2024
Tracked Since Feb 18, 2026