CVE-2024-40898
CriticalAdvisory
Published 18 Jul 2024In the index since 8 Sept 2026
- Severity
- Critical
- worst across findings
- CVSS
- 9.1
- base score, highest
- EPSS
- 0.015
- 73rd percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 8
- of 17,781 indexed, latest versions
- Container images
- 6
- deployed by those charts
- Fix available
- 2 of 2
- affected packages
Apache HTTP Server: SSRF with mod_rewrite in server/vhost context on Windows
Carried by container images the latest versions of 8 of 17,781 indexed charts deploy, on 6 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| apachebitnami | 2.4.54-157 | 2.4.62 | 1 |
| apache2apk | 2.4.54-r1, 2.4.57-r3, 2.4.58-r0, 2.4.59-r0 | 2.4.62-r0 | 5 |
- OSV records
- BIT-apache-2024-40898ALPINE-CVE-2024-40898
Charts affected
8 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| organizrgeek-cookbookVerified publisher | 7.4.2 | 1 of 1See more | 1,533 |
| equizequiz | 0.0.1 | 1 of 3See more | 7,541 |
| equizequiz-chart | 0.0.1 | 1 of 3See more | 7,541 |
| rtorrent-rutorrentgeek-cookbookVerified publisher | 1.1.2 | 1 of 1See more | 4,232 |
| organizrk8s-home-lab-repo | 8.1.1 | 1 of 1See more | 1,533 |
| freescoutl4gVerified publisher | 0.1.0 | 1 of 3See more | 5,332 |
| seashellpuckpuck | 1.2.0 | 1 of 1See more | 4,215 |
| grocysarab97Verified publisher | 0.1.1 | 1 of 1See more | 2,449 |
Container images carrying it
6 by charts deploying them
A fixed version is listed for 2 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| organizr/ | 1ce319d73cdf | apache2 | 2.4.62-r0 | 2 |
| yzhou442/ | a3f7ca69e28d | apache | 2.4.62 | 2 |
| crazymax/ | fb307f5b87bf | apache2 | 2.4.62-r0 | 1 |
| linuxserver/ | f8f5f96b6ea8 | apache2 | 2.4.62-r0 | 1 |
| tiredofit/ | 5b7cc0658f07 | apache2 | 2.4.62-r0 | 1 |
| ghcr.io/ | ef5e31333821 | apache2 | 2.4.62-r0 | 1 |