CVE-2021-40438
Vulnerability Summary
Timeline
Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVSS Metrics
- v3.1•CRITICAL•Score: 9CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
- v2.0•MEDIUM•Score: 6.8AV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 100.00%• Percentile: 100%
Techniques & Countermeasures
- CWE-918•Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
Affected Systems
- apache software foundation•apache http server
≥ Apache HTTP Server 2.4, ≤ 2.4.48
- apache•http_server
≤ 2.4.48
- alpine•apache2
< 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0 | < 2.4.49-r0
- broadcom•brocade_fabric_operating_system
na
- debian•apache2
< 2.4.51-1~deb11u1 | < 2.4.49-1 | < 2.4.49-1 | < 2.4.49-1
- debian•debian_linux
9.0 | 10.0 | 11.0
- f5•f5os
≥ 1.1.0, ≤ 1.1.4 | ≥ 1.2.0, ≤ 1.2.1
- fedoraproject•fedora
34 | 35
- netapp•cloud_backup
na
- netapp•clustered_data_ontap
na
- netapp•storagegrid
na
- oracle•enterprise_manager_ops_center
12.4.0.0
- oracle•http_server
12.2.1.3.0 | 12.2.1.4.0
- oracle•instantis_enterprisetrack
17.1 | 17.2 | 17.3
- oracle•secure_global_desktop
5.6
- oracle•zfs_storage_appliance_kit
8.8
- redhat•enterprise_linux
8.0
- redhat•enterprise_linux_eus
8.1 | 8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_for_arm_64
8.0
- redhat•enterprise_linux_for_arm_64_eus
8.6 | 8.8
- redhat•enterprise_linux_for_ibm_z_systems
7.0_s390x | 8.0
- redhat•enterprise_linux_for_ibm_z_systems_eus
8.1 | 8.4 | 8.8
- redhat•enterprise_linux_for_ibm_z_systems_eus_s390x
8.2
- redhat•enterprise_linux_for_power_big_endian
7.0
- redhat•enterprise_linux_for_power_little_endian
7.0 | 8.0
- redhat•enterprise_linux_for_power_little_endian_eus
8.1 | 8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_for_scientific_computing
7.0
- redhat•enterprise_linux_server
7.0
- redhat•enterprise_linux_server_aus
7.2 | 7.3 | 7.4 | 7.6 | 7.7 | 8.2 | 8.4 | 8.6
- redhat•enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
7.6 | 7.7 | 8.1 | 8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_server_tus
7.6 | 7.7 | 8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_server_update_services_for_sap_solutions
7.6 | 7.7
- redhat•enterprise_linux_update_services_for_sap_solutions
8.1 | 8.2 | 8.4 | 8.6 | 8.8
- redhat•enterprise_linux_workstation
7.0
- redhat•jboss_core_services
1.0
- redhat•software_collections
1.0
- resf•rocky_linux
8.0
- redhat•httpd
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-40.el7_2.7 | < 0:2.4.6-45.el7_3.6 | < 0:2.4.6-67.el7_4.7 | < 0:2.4.6-89.el7_6.2 | < 0:2.4.6-90.el7_7.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1
- redhat•httpd-debuginfo
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-40.el7_2.7 | < 0:2.4.6-45.el7_3.6 | < 0:2.4.6-67.el7_4.7 | < 0:2.4.6-89.el7_6.2 | < 0:2.4.6-90.el7_7.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1
- redhat•httpd-debugsource
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1
- redhat•httpd-devel
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-40.el7_2.7 | < 0:2.4.6-45.el7_3.6 | < 0:2.4.6-67.el7_4.7 | < 0:2.4.6-89.el7_6.2 | < 0:2.4.6-90.el7_7.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1
- redhat•httpd-filesystem
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1
- redhat•httpd-manual
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-40.el7_2.7 | < 0:2.4.6-45.el7_3.6 | < 0:2.4.6-67.el7_4.7 | < 0:2.4.6-89.el7_6.2 | < 0:2.4.6-90.el7_7.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1
- redhat•httpd-tools
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-40.el7_2.7 | < 0:2.4.6-45.el7_3.6 | < 0:2.4.6-67.el7_4.7 | < 0:2.4.6-89.el7_6.2 | < 0:2.4.6-90.el7_7.1 | < 0:2.4.6-97.el7_9.1 | < 0:2.4.6-97.el7_9.1
- redhat•httpd-tools-debuginfo
< 0:2.4.37-21.module+el8.2.0+12904+53ee7aba.1 | < 0:2.4.37-16.module+el8.1.0+12900+7e6e5641.1
- redhat•httpd24-httpd
< 0:2.4.34-22.el7.1
- redhat•httpd24-httpd-debuginfo
< 0:2.4.34-22.el7.1
- redhat•httpd24-httpd-devel
< 0:2.4.34-22.el7.1
- redhat•httpd24-httpd-manual
< 0:2.4.34-22.el7.1
- redhat•httpd24-httpd-tools
< 0:2.4.34-22.el7.1
Showing first 50 affected entries in server-rendered view.
References (38)
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
- https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E
- https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
- https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html
- https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E
- https://www.debian.org/security/2021/dsa-4982
- https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E
- https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.tenable.com/security/tns-2021-17
- https://security.netapp.com/advisory/ntap-20211008-0004/
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://security.gentoo.org/glsa/202208-20
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40438
- https://access.redhat.com/errata/RHSA-2021:3746
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2005117
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3746.json
- https://access.redhat.com/security/cve/CVE-2021-40438
- https://www.cve.org/CVERecord?id=CVE-2021-40438
- https://nvd.nist.gov/vuln/detail/CVE-2021-40438
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://access.redhat.com/errata/RHSA-2021:3754
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3754.json
- https://access.redhat.com/errata/RHSA-2021:3836
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3836.json
- https://access.redhat.com/errata/RHSA-2021:3837
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3837.json
- https://access.redhat.com/errata/RHSA-2021:3856
- https://security.access.redhat.com/data/csaf/v2/advisories/2021/rhsa-2021_3856.json
- https://security-tracker.debian.org/tracker/CVE-2021-40438
- https://security.alpinelinux.org/vuln/CVE-2021-40438