PT-2021-1392 · Apache+9 · Apache Http Server+9

The Apache

·

Published

2021-09-16

·

Updated

2026-03-10

·

CVE-2021-40438

CVSS v3.1

9.0

Critical

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Apache HTTP Server versions 2.4.48 and earlier
Description: A crafted request uri-path can cause mod proxy to forward the request to an origin server chosen by the remote user. This issue is related to insufficient validation of incoming requests, allowing a remote attacker to perform a Server-Side Request Forgery (SSRF) attack. The estimated number of potentially affected devices worldwide is not specified. There are reports of real-world incidents where this issue was exploited.
Recommendations: For Apache HTTP Server versions 2.4.48 and earlier, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the mod proxy module to minimize the risk of exploitation. Avoid using vulnerable configurations that allow an attacker to manipulate the request uri-path until the issue is resolved.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

ALBA-2021:4604
ALSA-2021:3816
ALSA-2021:4537
ALSA-2021_3816
ALSA-2022_0258
ALSA-2022_1049
ALSA-2023_1670
ALSA-2023_1673
ALSA-2025_16880
ALT-PU-2021-2866
ALT-PU-2021-2972
ALT-PU-2021-3037
ALT-PU-2021-3060
AZL-6487
BDU:2021-04820
BIT-APACHE-2021-40438
CESA-2021_3816
CESA-2021_3856
CVE-2021-40438
DLA-2776-1
DSA-4982-1
ELSA-2021-3816
ELSA-2021-3856
MGASA-2021-0439
OESA-2021-1369
OPENSUSE-SU-2021:1438-1
OPENSUSE-SU-2021:3522-1
OPENSUSE-SU-2021_1438-1
OPENSUSE-SU-2021_3522-1
OPENSUSE-SU-2025:14708-1
RHSA-2021:3746
RHSA-2021:3754
RHSA-2021:3816
RHSA-2021:3836
RHSA-2021:3837
RHSA-2021:3856
RHSA-2021_3816
RHSA-2021_3856
RLSA-2021:3816
RLSA-2021_3816
ROSA-SA-2023-2158
SUSE-SU-2021:3299-1
SUSE-SU-2021:3335-1
SUSE-SU-2021:3522-1
SUSE-SU-2021_3299-1
SUSE-SU-2021_3335-1
SUSE-SU-2021_3522-1
USN-5090-1
USN-5090-2
USN-5090-3
USN-5090-4
ZDI-24-812

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu