cbcvebase.
CVE-2021-40438
published 2021-09-16

CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server…

PriorityP198critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2021-12-15
Exploited in the wild
EPSS
100.00%
100.0th percentile
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected

86 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server<= 2.4.48
apachehttpd
apache_software_foundationapache_http_serverApache HTTP Server 2.4 – 2.4.48
debianapache2< apache2 2.4.49-1 (bookworm)apache2 2.4.49-1 (bookworm)
debianapache2
debiandebian_linux
debiandebian_linux
debiandebian_linux
f5f5os1.1.0 – 1.1.4
f5f5os1.2.0 – 1.2.1
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.52-1_on_cbl_mariner_2.0
msrccm1_httpd_2.4.49-1_on_cbl_mariner_1.0
oracleenterprise_manager_ops_center
oraclehttp_server
oraclehttp_server
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oraclesecure_global_desktop
oraclezfs_storage_appliance_kit
paloaltopan-os
redhatenterprise_linux
redhatenterprise_linux

Detection & IOCsextracted from sources · hover to see the quote

ip169.254.169.254
filenameinit.sh
port4040
filenameipranges.txt
  • Trend Micro Workload Security Intrusion Prevention filter 1011183 detects CVE-2021-40438 SSRF exploitation attempts against Apache HTTP Server mod_proxy.
  • Trend Micro Network Security filter 40421 detects the long UDS path name proxy request pattern used to exploit CVE-2021-40438.
  • Exploitation of CVE-2021-40438 observed in the wild targeting the AWS IMDS link-local address (169.254.169.254) via SSRF through mod_proxy to steal EC2 instance credentials.
  • Detect use of masscan and zgrab scanning for Weave Scope UI on ports 80, 443, and 4040 as post-exploitation lateral movement/reconnaissance activity.
  • The CVE-2021-40438 vulnerability is in the mod_proxy module; a crafted request uri-path causes Apache to forward requests to an attacker-chosen origin server (SSRF). Inspect proxy request URI paths for anomalous or oversized UDS path components.
  • ·CVE-2021-40438 affects Apache HTTP Server versions 2.4.48 and earlier; the mod_proxy module must be enabled for the vulnerability to be exploitable.
  • ·SSRF exploitation targeting AWS IMDS is only impactful if IMDSv2 is not enforced; restricting to IMDSv2 prevents credential enumeration via this attack path.

CVSS provenance

nvdv3.19.0CRITICALCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.0CRITICAL
vulncheck9.0CRITICAL
cisa9.0CRITICAL
vendor_debian9.8LOW
vendor_redhat9.8CRITICAL
vendor_cisco9.0CRITICAL
vendor_msrc9.0CRITICAL
vendor_oracle9.0CRITICAL
vendor_apache7.5HIGH
vendor_ubuntu7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.