Junglewise Threat Intelligence

CVE-2021-40438: Apache HTTP Server-Side Request Forgery (SSRF)

CVE-2021-40438 · Severity: critical · CVSS 9 · Exploited in the wild · Published 2021-12-01

Technologies: Apache HTTP Server. Vendors: Apache.

Executive brief

A Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server's mod_proxy module allows a remote attacker to forward requests to an arbitrary origin server via a crafted request uri-path. This flaw can lead to unauthorized access to internal systems or data exfiltration.

Affected products

  • Apache HTTP Server 2.4.48 and earlier

Timeline

  • 2021-12-01: disclosed
  • 2021-12-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-12-01: exploited: Confirmed exploited in the wild per CISA KEV catalog.