Hello All,
Does anyone have some information about this Apache Vulnerabilities?
Affecting Apache HTTP Server versions 2.4.0 through 2.4.61
As I checked the newest hotfix Take 76 for R81.20 haven't update for Apache HTTPD.
Details:
- CVE-2024-40725: This vulnerability concerns an incomplete fix for a previous vulnerability (CVE-2024-39884) and affects the mod_proxy module. It allows attackers to potentially disclose sensitive source code information on the server under specific circumstances. This could include PHP scripts or other server-side files. This affects both Windows and Linux systems.
- CVE-2024-40898: This vulnerability affects Apache HTTP Server on Windows systems with mod_rewrite in server/vhost context. A malicious actor could exploit this vulnerability to launch Server-Side Request Forgery (SSRF) attacks. This could potentially lead to leaking NTLM hashes or other sensitive information.