TROYANOSYVIRUS
Volver a CVEs

CVE-2021-40438

CRITICALCISA KEV
9.0

Descripcion

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Detalles CVE

Puntuacion CVSS v3.19.0
SeveridadCRITICAL
Vector CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vector de ataqueNETWORK
ComplejidadHIGH
Privilegios requeridosNONE
Interaccion usuarioNONE
Publicado9/16/2021
Ultima modificacion10/27/2025
Fuentekev
Avistamientos honeypot0

CISA KEV

VendedorApache
ProductoApache
Nombre vulnerabilidadApache HTTP Server-Side Request Forgery (SSRF)
Fecha inclusion KEV2021-12-01
Fecha limite remediacion2021-12-15
Uso en ransomwareUnknown

Productos afectados

apache:http_serverbroadcom:brocade_fabric_operating_system_firmwaredebian:debian_linuxf5:f5osfedoraproject:fedoranetapp:cloud_backupnetapp:clustered_data_ontapnetapp:storagegridoracle:enterprise_manager_ops_centeroracle:http_serveroracle:instantis_enterprisetrackoracle:secure_global_desktoporacle:zfs_storage_appliance_kitredhat:enterprise_linuxredhat:enterprise_linux_eusredhat:enterprise_linux_for_arm_64redhat:enterprise_linux_for_arm_64_eusredhat:enterprise_linux_for_ibm_z_systemsredhat:enterprise_linux_for_ibm_z_systems_eusredhat:enterprise_linux_for_ibm_z_systems_eus_s390xredhat:enterprise_linux_for_power_big_endianredhat:enterprise_linux_for_power_little_endianredhat:enterprise_linux_for_power_little_endian_eusredhat:enterprise_linux_for_scientific_computingredhat:enterprise_linux_serverredhat:enterprise_linux_server_ausredhat:enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutionsredhat:enterprise_linux_server_tusredhat:enterprise_linux_server_update_services_for_sap_solutionsredhat:enterprise_linux_server_workstationredhat:enterprise_linux_update_services_for_sap_solutionsredhat:enterprise_linux_workstationredhat:jboss_core_servicesredhat:software_collectionsresf:rocky_linuxsiemens:ruggedcom_nmssiemens:sinec_nmssiemens:sinema_remote_connect_serversiemens:sinema_servertenable:tenable.sc

Debilidades (CWE)

CWE-918CWE-918

Referencias

https://httpd.apache.org/security/vulnerabilities_24.html(af854a3a-2127-422b-91ae-364da2661108)
https://security.gentoo.org/glsa/202208-20(af854a3a-2127-422b-91ae-364da2661108)
https://security.netapp.com/advisory/ntap-20211008-0004/(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2021/dsa-4982(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpuapr2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.oracle.com/security-alerts/cpujan2022.html(af854a3a-2127-422b-91ae-364da2661108)
https://www.tenable.com/security/tns-2021-17(af854a3a-2127-422b-91ae-364da2661108)

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.