CVE-2021-40438
Apache HTTP Server-Side Request Forgery (SSRF)
CVSS
9.0
Crítico
EPSS
100.0%
p100
KEV
SÍ
1 dic 2021
Exploit Today
80
0-100
Publicado: 16 sept 2021 · Última mod.: 6 ago 2026 · CWE-918
Producto
Apache / Apache
Vulnerabilidad
Apache HTTP Server-Side Request Forgery (SSRF)
Añadido a KEV
1 dic 2021
Remediar antes de
15 dic 2021
Uso conocido en ransomware
Sí
Descripción resumida
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Acción requerida
Apply updates per vendor instructions.
Notas
https://nvd.nist.gov/vuln/detail/CVE-2021-40438
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- httpd.apache.orghttps://httpd.apache.org/security/vulnerabilities_24.html
- lists.apache.orghttps://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E
- lists.apache.orghttps://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E
- lists.debian.orghttps://lists.debian.org/debian-lts-announce/2021/10/msg00001.html
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
- lists.fedoraproject.orghttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
- security.gentoo.orghttps://security.gentoo.org/glsa/202208-20
- security.netapp.comhttps://security.netapp.com/advisory/ntap-20211008-0004/
- tools.cisco.comhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
- www.debian.orghttps://www.debian.org/security/2021/dsa-4982
- www.oracle.comhttps://www.oracle.com/security-alerts/cpuapr2022.html
- www.oracle.comhttps://www.oracle.com/security-alerts/cpujan2022.html
- www.tenable.comhttps://www.tenable.com/security/tns-2021-17
- cert-portal.siemens.comhttps://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf