Release of Apache HTTP Server 2.4.62 addressing 2 vulnerabilities.
The release of the Apache HTTP Server 2.4.62 is now available, addressing two vulnerabilities and implementing six changes. The first vulnerability (CVE-2024-40898) allows for an SSRF (Server-side request forgery) attack on mod_rewrite. This issue only appears on the Windows platform and can cause the leakage of NTLM hashes to a server under the attacker's control when specially crafted requests are sent. The second vulnerability (CVE-2024-40725) enables viewing the code of scripts being processed […]
