Severity
8.2HIGH
EPSS
11.0%
top 6.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 20
Latest updateMay 16

Description

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 3.9 | Impact: 4.2

Affected Packages13 packages

NVDapache/http_server2.4.72.4.52
CVEListV5apache_software_foundation/apache_http_server2.4.7Apache HTTP Server 2.4*
NVDoracle/http_server12.2.1.3.0, 12.2.1.4.0+1
Debianapache2< 2.4.52-1~deb11u2+3
Ubuntuapache2< 2.4.29-1ubuntu4.21+3

Also affects: Debian Linux 10.0, 11.0, Fedora 34, 35, 36

Patches

🔴Vulnerability Details

5
GHSA
GHSA-92ww-hwmg-qq7p: A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixin2022-02-08
OSV
apache2 vulnerabilities2022-01-10
OSV
apache2 vulnerabilities2022-01-06
OSV
CVE-2021-44224: A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixin2021-12-20
CVEList
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier2021-12-20

📋Vendor Advisories

9
Apple
CVE-2021-44224: Security Update 2022-004 Catalina2022-05-16
Apple
CVE-2021-44224: macOS Big Sur 11.6.62022-05-16
Apple
CVE-2021-44224: macOS Monterey 12.42022-05-16
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) — CVE-2021-442242022-04-15
Ubuntu
Apache HTTP Server vulnerabilities2022-01-10