Skip to content
COOEY

EXPOSURES › CVE-2021-40438

CVE-2021-40438

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-40438 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

Apache HTTP Server 2.4.48 and earlier suffered an SSRF vulnerability allowing attackers to bypass proxy restrictions and access internal systems.

An SSRF flaw in Apache HTTP Server's mod_proxy module let attackers craft malicious URI paths to force the server to forward requests to arbitrary origin servers, bypassing security controls. DIB organizations must ensure their web infrastructure is patched to prevent attackers from using SSRF to pivot into internal networks or exfiltrate sensitive data. This vulnerability was actively exploited in the wild, highlighting the risk of relying on unpatched open-source components.

Shame score — The vulnerability was actively exploited in the wild (KEV) and affected a widely deployed open-source product, demonstrating a failure to patch known, high-severity flaws in critical infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Apache faced severe fallout due to a critical SSRF vulnerability in mod_proxy, allowing remote attackers to bypass security controls and access internal resources. The vulnerability affected widely de
cooey ↗ severe-fallout -0.60
severe-fallout
"A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier."
AFFECTED FEDRAMP PRODUCTS · 17
PRODUCTSTATUS
Aconex for Defense
Oracle
Authorized
Clarity
Broadcom
Authorized
Cloud Insights
NetApp
In Process
Federal Managed Cloud Services
Oracle
Authorized
Fusion Cloud
Oracle
Authorized
General Support Systems (GSS)
Broadcom
Authorized
Government Cloud - Common Controls
Oracle
Authorized
Mendix Cloud for Government
Siemens Government Technologies
In Process
Oracle Cloud Infrastructure-Government Cloud
Oracle
Authorized
Oracle Enterprise Performance Management (EPM)
Oracle
Authorized
Oracle Enterprise Performance Management (EPM) - Moderate
Oracle
In Process
Oracle Service Cloud
Oracle
Authorized
Oracle Service Cloud (DOD)
Oracle
Authorized
Rally
Broadcom
Authorized
Symantec Gov Cloud Security (GCS)
Broadcom
In Process
Taleo Cloud - U.S. Government Cloud
Oracle
Authorized
Tenable.io
Tenable Public Sector (TPS)
Authorized