logo
Home/CVEs/CVE-2021-40438/

CVE-2021-40438 - Apache HTTP Server-Side Request Forgery (SSRF)

Project:Apache

Product:Apache

Date Added:2021-12-01Due Date:2021-12-15

Vulnerability Name

Apache HTTP Server-Side Request Forgery (SSRF)

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Known To Be Used in Ransomware Campaigns?

Unknown

Action

Apply updates per vendor instructions.

Additional Notes

https://nvd.nist.gov/vuln/detail/CVE-2021-40438