CRITICAL

CVE-2021-40438

Redhat Enterprise Linux 2021-09-16 CVSS v3.1
CVSS
9
KEV

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Summary dbcve.org

This is a server-side request forgery (SSRF) vulnerability in Apache's mod_proxy module. A remote attacker can craft a malicious request URI-path to force the server to forward HTTP requests to an origin server of their choosing, potentially enabling access to internal services and systems.

Mitigation

Upgrade Apache HTTP Server to version 2.4.49 or later, which contains the fix for this vulnerability.

Patch Commit

Weakness (CWE)

CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

100%
Probability of exploitation in next 30 days
100th percentile

References

https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf Third Party Advisory https://httpd.apache.org/security/vulnerabilities_24.html Release Notes, Vendor Advisory https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E Mailing List https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E Mailing List https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E Mailing List https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E Mailing List https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E Mailing List https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E Mailing List https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E Mailing List https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html Mailing List, Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/ Release Notes https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/ Release Notes https://security.gentoo.org/glsa/202208-20 Third Party Advisory https://security.netapp.com/advisory/ntap-20211008-0004/ Third Party Advisory https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ Broken Link, Third Party Advisory https://www.debian.org/security/2021/dsa-4982 Mailing List, Third Party Advisory https://www.oracle.com/security-alerts/cpuapr2022.html Patch, Third Party Advisory https://www.oracle.com/security-alerts/cpujan2022.html Patch, Third Party Advisory https://www.tenable.com/security/tns-2021-17 Third Party Advisory https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40438 US Government Resource
View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE