
The version of Tencent Linux installed on the remote TencentOS Server 4 host is prior to tested version. It is, therefore, affected by multiple vulnerabilities as referenced in the TSSA-2024:0499 advisory. Package updates are available for TencentOS Server 4 that fix the following vulnerabilities: CVE-2024-36387: Serving WebSocket protocol upgrades over a HTTP/2 connection could result in a Null Pointer dereference, leading to a crash of the server process, degrading performance. CVE-2024-38472: SSRF in Apache HTTP Server on Windows allows to potentially leak NTML hashes to a malicious server via SSRF andmalicious requests or content Users are recommended to upgrade to version 2.4.60 which fixes this issue. Note: Existing configurations that access UNC paths will have to configure new directive UNCList to allow access during request processing. Tenable has extracted the preceding description block directly from the Tencent Linux security advisory. Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version…Read More
References
Back to Main