CVE-2021-40438

Related Vulnerabilities: CVE-2021-40438  

A Server-Side Request Forgery (SSRF) flaw was found in mod_proxy of httpd. This flaw allows a remote unauthenticated attacker to forward requests to an arbitrary origin server. The highest threat from this vulnerability is to confidentiality.

Description

A Server-Side Request Forgery (SSRF) flaw was found in mod_proxy of httpd. This flaw allows a remote unauthenticated attacker to forward requests to an arbitrary origin server. The highest threat from this vulnerability is to confidentiality.

Additional Information

  • Bugzilla 2005117: CVE-2021-40438 httpd: mod_proxy: SSRF via a crafted request uri-path
  • CWE-918: Server-Side Request Forgery (SSRF)
  • FAQ: Frequently asked questions about CVE-2021-40438