⚠ Actively exploited
Added to CISA KEV on 2021-12-01. Federal agencies required to patch by 2021-12-15. Required action: Apply updates per vendor instructions..
Severity
9.0CRITICAL
EPSS
94.4%
top 0.01%
CISA KEV
KEV
Added 2021-12-01
Due 2021-12-15
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 16
KEV addedDec 1
KEV dueDec 15
Latest updateJul 13
CISA Required Action: Apply updates per vendor instructions.

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 2.2 | Impact: 6.0

Affected Packages18 packages

NVDapache/http_server2.4.48
CVEListV5apache_software_foundation/apache_http_serverApache HTTP Server 2.42.4.48
NVDoracle/http_server12.2.1.3.0, 12.2.1.4.0+1

Also affects: Rocky Linux 8.0, Debian Linux 10.0, 11.0, 9.0, Fedora 34, 35, Enterprise Linux 8.0, 8.1, 8.2, 8.4, 8.6, 8.8, 7.0, 7.2, 7.3, 7.4, 7.6, 7.7

Patches

🔴Vulnerability Details

4
GHSA
GHSA-rwxq-58vm-3v2j: A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user2022-05-24
CVEList
mod_proxy SSRF2021-09-16
OSV
CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user2021-09-16
VulnCheck
Apache HTTP Server-Side Request Forgery (SSRF)2021

💥Exploits & PoCs

1
Nuclei
Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery

🔍Detection Rules

1
Suricata
ET EXPLOIT Apache HTTP Server SSRF (CVE-2021-40438)2021-11-30

📋Vendor Advisories

11
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: User Interface (Apache HTTP Server) — CVE-2021-404382022-04-15
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: OSSL Module (Apache HTTP Server) — CVE-2021-404382022-01-15
CISA
Apache HTTP Server-Side Request Forgery (SSRF)2021-12-01
Cisco
Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 20212021-11-24
Red Hat
httpd: Regression of CVE-2021-40438 and CVE-2021-26691 fixes in Red Hat Enterprise Linux 8.52021-11-09

🕵️Threat Intelligence

1
Unit42
Network Security Trends: August-October 20212021-12-21

💬Community

1
HackerOne
CVE-2021-40438 on cp-eu2.acronis.com2022-07-13