CVE-2021-40438
Apache HTTP Server-Side Request Forgery (SSRF)
CVSS
9.0
Critical
EPSS
100.0%
p100
KEV
YES
Dec 1, 2021
Exploit Today
80
0-100
Published: Sep 16, 2021 · Last modified: Aug 6, 2026 · CWE-918
Product
Apache / Apache
Vulnerability
Apache HTTP Server-Side Request Forgery (SSRF)
Added to KEV
Dec 1, 2021
Remediate by
Dec 15, 2021
Known ransomware use
Yes
Summary description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Required action
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2021-40438
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- httpd.apache.orghttps://httpd.apache.org/security/vulnerabilities_24.html
- lists.apache.orghttps://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2021/10/msg00001.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
- security.gentoo.orghttps://security.gentoo.org/glsa/202208-20
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20211008-0004/
- tools.cisco.comhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
- www.debian.orghttps://www.debian.org/security/2021/dsa-4982
- www.oracle.comhttps://www.oracle.com/security-alerts/cpuapr2022.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpujan2022.html
- www.tenable.comhttps://www.tenable.com/security/tns-2021-17
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf