EXPOSURES › CVE-2021-40438
CVE-2021-40438
HIGH ⌖ ON CISA KEV · EXPLOITEDApache HTTP Server 2.4.48 and earlier suffered an SSRF vulnerability allowing attackers to bypass proxy restrictions and access internal systems.
An SSRF flaw in Apache HTTP Server's mod_proxy module let attackers craft malicious URI paths to force the server to forward requests to arbitrary origin servers, bypassing security controls. DIB organizations must ensure their web infrastructure is patched to prevent attackers from using SSRF to pivot into internal networks or exfiltrate sensitive data. This vulnerability was actively exploited in the wild, highlighting the risk of relying on unpatched open-source components.
Shame score — The vulnerability was actively exploited in the wild (KEV) and affected a widely deployed open-source product, demonstrating a failure to patch known, high-severity flaws in critical infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
"A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier."
| PRODUCT | STATUS |
|---|---|
| Aconex for Defense Oracle |
Authorized |
| Clarity Broadcom |
Authorized |
| Cloud Insights NetApp |
In Process |
| Federal Managed Cloud Services Oracle |
Authorized |
| Fusion Cloud Oracle |
Authorized |
| General Support Systems (GSS) Broadcom |
Authorized |
| Government Cloud - Common Controls Oracle |
Authorized |
| Mendix Cloud for Government Siemens Government Technologies |
In Process |
| Oracle Cloud Infrastructure-Government Cloud Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) Oracle |
Authorized |
| Oracle Enterprise Performance Management (EPM) - Moderate Oracle |
In Process |
| Oracle Service Cloud Oracle |
Authorized |
| Oracle Service Cloud (DOD) Oracle |
Authorized |
| Rally Broadcom |
Authorized |
| Symantec Gov Cloud Security (GCS) Broadcom |
In Process |
| Taleo Cloud - U.S. Government Cloud Oracle |
Authorized |
| Tenable.io Tenable Public Sector (TPS) |
Authorized |