cbcvebase.
CVE-2021-40438
published 2021-09-16

CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server…

critical9CVSS 3.1
AVNACHPRNUINSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2021-12-15
Exploited in the wild
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected

86 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server<= 2.4.48
apachehttpd
apache_software_foundationapache_http_serverApache HTTP Server 2.4 – 2.4.48
debianapache2< apache2 2.4.49-1 (bookworm)apache2 2.4.49-1 (bookworm)
debianapache2
debiandebian_linux
debiandebian_linux
debiandebian_linux
f5f5os1.1.0 – 1.1.4
f5f5os1.2.0 – 1.2.1
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.52-1_on_cbl_mariner_2.0
msrccm1_httpd_2.4.49-1_on_cbl_mariner_1.0
oracleenterprise_manager_ops_center
oraclehttp_server
oraclehttp_server
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oraclesecure_global_desktop
oraclezfs_storage_appliance_kit
paloaltopan-os
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.0CRITICAL
vulncheck9.0CRITICAL
cisa9.0CRITICAL