CVE-2021-40438
KEV ransomwaremassServer-Side Request Forgery (SSRF) in Apache HTTP Server mod_proxy
CISA: Apache HTTP Server-Side Request Forgery (SSRF)
CVE-2021-40438 is a server-side request forgery flaw (CWE-918) in the mod_proxy module of Apache HTTP Server 2.4.48 and earlier. By sending a crafted request URI path, a remote attacker can cause the server to forward the request to an origin server chosen by the attacker instead of the intended backend. This lets the attacker use the web server as a proxy to reach internal network services, probe internal hosts, and bypass network access controls. Anyone running an affected Apache HTTP Server version with mod_proxy enabled in a proxying configuration is affected. The flaw is being actively exploited in the wild - it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-12-01 with known ransomware use - and EPSS assigns it the highest probability of near-term exploitation.
What to do: Upgrade Apache HTTP Server to a release newer than 2.4.48 per vendor instructions. As an interim mitigation, restrict mod_proxy so it forwards only to explicitly configured backends (avoiding attacker-controlled origin selection) or disable mod_proxy where it is not required, and audit internet-facing Apache servers for proxy configurations. Because this flaw is on the CISA KEV list with known ransomware use, prioritize patching internet-facing systems immediately.
| Apache HTTP Server | 2.4.48 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- Affected
- Apache Apache
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Known
- Vendors
- resfredhatapachefedoraprojectdebiannetappbroadcomf5oraclesiemenstenable
- Products
- rocky linux, enterprise linux, enterprise linux eus, enterprise linux for arm 64, enterprise linux for arm 64 eus, enterprise linux for ibm z systems, enterprise linux for ibm z systems eus, enterprise linux for ibm z systems eus s390x, enterprise linux for power big endian, enterprise linux for power little endian, enterprise linux for power little endian eus, enterprise linux for scientific computing
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H