← Back

CVE-2021-40438

Published: Sep 16, 2021Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
9.0
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 6.0
Source: NVD

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected (81)

Show all products
1 product
Rocky Linux
18 products
1 product
Http Server
1 product
Fedora
1 product
Debian Linux
1 product
3 products
Cloud Backup
Clustered Data Ontap
Storagegrid
1 product
F5os
5 products
Enterprise Manager Ops Center
Http Server
Instantis Enterprisetrack
Secure Global Desktop
Zfs Storage Appliance Kit
4 products
Ruggedcom Nms
Sinec Nms
Sinema Remote Connect Server
Sinema Server
1 product
Tenable.sc
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0
Configuration B
52 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 8.0
Redhat
Version 8.6
Version 8.8
Redhat
Version 7.0_s390x
Version 8.0
Redhat
Version 8.1
Version 8.4
Version 8.8
Version 8.2
Version 7.0
Redhat
Version 7.0
Version 8.0
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 7.0
Redhat
Version 7.2
Version 7.3
Version 7.4
Version 7.6
Version 7.7
Version 8.2
Version 8.4
Version 8.6
Redhat
Version 7.6
Version 7.7
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 7.6
Version 7.7
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Redhat
Version 7.6
Version 7.7
Redhat
Version 8.1
Version 8.2
Version 8.4
Version 8.6
Version 8.8
Version 7.0
Configuration C
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 1.0
Running on/withPlatform Versions
Redhat
Enterprise Linux
Version 7.0
Redhat
Enterprise Linux
Version 8.0
Configuration D
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Version 1.0
Running on/withPlatform Versions
Redhat
Enterprise Linux Server
Version 7.0
Redhat
Enterprise Linux Server Workstation
Version 7.0
Configuration E
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 2.4.48
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Configuration G
3 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Version 9.0
Configuration H
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
All versions
All versions
All versions
Configuration I
2 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 1.1.0 to 1.1.4
From 1.2.0 to 1.2.1
Configuration J
8 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.4.0.0
Oracle
Version 12.2.1.3.0
Version 12.2.1.4.0
Oracle
Version 17.1
Version 17.2
Version 17.3
Version 5.6
Version 8.8
Configuration K
5 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Before 1.0.3
Siemens
Before 3.1
Version 3.2
Version 14.0
Configuration L
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 5.19.1

References (39)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.