Executive brief
A Server-Side Request Forgery (SSRF) vulnerability in Apache HTTP Server's mod_proxy module allows a remote attacker to forward requests to an arbitrary origin server via a crafted request uri-path. This flaw can lead to unauthorized access to internal systems or data exfiltration.
Affected products
- Apache HTTP Server 2.4.48 and earlier
Timeline
- 2021-12-01: disclosed
- 2021-12-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-12-01: exploited: Confirmed exploited in the wild per CISA KEV catalog.