CVE-2024-38472 is a Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server on Windows, allowing for the potential leakage of NTLM hashes to a malicious server. This high-severity vulnerability (CVSS 7.5) has a low attack complexity and can lead to significant information disclosure. While not currently in the KEV catalog, Nuclei templates exist for detecting this flaw, and it has garnered notable community discussion and media coverage, indicating active awareness. Users are advised to upgrade to version 2.4.60, configuring the new "UNCList" directive if UNC paths are in use.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.0, < 2.4.60CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
9CPE matchmatch criteria | cpe:2.3:a:netapp:ontap:9:*:*:*:*:*:*:* | ||
>= 2.4.0, <= 2.4.59CPE match | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025CVE-2024-38472
Dec 10, 2024httpd: SSRF in Apache HTTP Server on Windows
Jul 1, 2024Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project