CyberzSOC

Publication detail
← Back to advisories & guidance

2024-073: Apache HTTP Server Critical Vulnerabilities ↗ source

July 24, 2024 CERT-EU Advisory

Summary

These vulnerabilities can lead to HTTP request smuggling and SSL client authentication bypass, potentially resulting in unauthorised access and other malicious activities [1]. It is recommended to update affected systems immediately. allows source code disclosure via certain legacy content-type-based configuration settings. Exploitation of these vulnerabilities could allow attackers to gain unauthorised access, perform session hijacking, cross-site scripting (XSS), or command injection. More information about the attack method can be found here [2]. An open-source vulnerability checker is available on github [3].

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-40898 9.1 Critical Apache Software Foundation Apache HTTP Server SSRF in Apache HTTP Server on Windows with mod_rewrite in server/vhost context, allows to potentially leak NTML hashes to a malicious server via SSRF…
CVE-2024-40725 5.3 Medium Apache Software Foundation Apache HTTP Server A partial fix for  CVE-2024-39884 in the core of Apache HTTP Server 2.4.61 ignores some use of the legacy content-type based configuration of handler…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.