CVE-2021-40438: mod_proxy SSRF
A crafted request uri-path can cause modproxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Other sources
A Server-Side Request Forgery (SSRF) flaw was found in modproxy of httpd. This flaw allows a remote, unauthenticated attacker to make the httpd server forward requests to an arbitrary server. The attacker could get, modify, or delete resources on other services that may be behind a firewall and inaccessible otherwise. The impact of this flaw varies based on what services and resources are available on the httpd network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-76.el8 - Upgrade
Upgrade
redhat/jbcs-httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.37-76.jbcs.el7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-97.el7_9.1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-40.el7_2.7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-45.el7_3.6 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-67.el7_4.7 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-89.el7_6.2 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 0:2.4.6-90.el7_7.1 - Upgrade
Upgrade
redhat/httpd24-httpdto a version that resolves this vulnerability.Fixed in 0:2.4.34-22.el7.1 - Upgrade
Upgrade
debian/apache2to a version that resolves this vulnerability.Fixed in 2.4.38-3+deb10u8Fixed in 2.4.38-3+deb10u10Fixed in 2.4.56-1~deb11u2Fixed in 2.4.56-1~deb11u1Fixed in 2.4.57-2Fixed in 2.4.57-3Fixed in 2.4.58-1 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.49 - Upgrade
Upgrade
Apache HTTP Server (httpd) mod_proxyto a version that resolves this vulnerability.Fixed in 2.4.49
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-40438?
CVE-2021-40438 is a Server-Side Request Forgery (SSRF) vulnerability found in Apache HTTP Server (httpd) that allows a remote attacker to make the server forward requests to an arbitrary server.
How severe is CVE-2021-40438?
CVE-2021-40438 has a severity level of critical, with a CVSS score of 9.0.
Which software versions are affected by CVE-2021-40438?
CVE-2021-40438 affects Apache HTTP Server (httpd) versions up to and including 2.4.49.
How can I fix CVE-2021-40438?
To fix CVE-2021-40438, upgrade to Apache HTTP Server (httpd) version 2.4.49 or apply the recommended patches provided by your software vendor.
Where can I find more information about CVE-2021-40438?
You can find more information about CVE-2021-40438 on the Apache HTTP Server security vulnerabilities page and the Red Hat Bugzilla page.