Umbra Wiki cve cve/CVE-2021-40438
Back to wiki

CVE-2021-40438 — Apache HTTP Server-Side Request Forgery (SSRF)

provenance: imported · CVE: CVE-2021-40438

CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)

CISA Known Exploited Vulnerability (KEV)

Vendor / project Apache
Product Apache
Date added 2021-12-01
Due date 2021-12-15
Ransomware campaign use Known

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Required action (CISA)

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2021-40438

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2021-40438
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog