Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
4mon
Participant

Apache High-severity Vulnerabilities: CVE-2024-40725 CVE-2024-39884 CVE-2024-40898

Hello All,
Does anyone have some information about this Apache Vulnerabilities?
Affecting Apache HTTP Server versions 2.4.0 through 2.4.61
As I checked the newest hotfix Take 76 for R81.20 haven't update for Apache HTTPD.

Details:

  • CVE-2024-40725: This vulnerability concerns an incomplete fix for a previous vulnerability (CVE-2024-39884) and affects the mod_proxy module. It allows attackers to potentially disclose sensitive source code information on the server under specific circumstances. This could include PHP scripts or other server-side files. This affects both Windows and Linux systems.
  • CVE-2024-40898: This vulnerability affects Apache HTTP Server on Windows systems with mod_rewrite in server/vhost context. A malicious actor could exploit this vulnerability to launch Server-Side Request Forgery (SSRF) attacks. This could potentially lead to leaking NTLM hashes or other sensitive information.

 

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I’m fairly certain we do not use either mod_rewrite or mod_proxy in our Apache implementation. 
That makes both of these CVEs not relevant for Gaia OS.

For formal confirmation I recommend a TAC case: https://help.checkpoint.com

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events