Back

CRITICAL KEV Used in ransomware campaigns

mod_proxy SSRF

Published Sep 16, 2021 ·Due Dec 15, 2021

Description

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected products

Remediation

Red Hat statement

Impact of the flaw set to Important because the actions an attacker can do varies a lot based on the kind of infrastructure in place, the kind of internal services and resources, and the available endpoints on those services. The attacker should also perform some kind of target-specific reconnaissance in order to find out all the above information. The version of httpd as shipped in Red Hat Enterprise Linux 7 is affected by this flaw even if the upstream code was not, because the Unix Domain Socket support required to trigger the flaw was backported. The version of httpd as shipped in Red hat Enterprise Linux 6 is not affected by this flaw because there is no support for Unix Domain Socket. The flaw can be triggered only if mod_proxy is in use (e.g. ProxyPass, ReverseProxy is used in the httpd configuration files).

Red Hat mitigation

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.

Metrics

Weaknesses (1)

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 16, 2021
Updated Aug 6, 2026
Reserved Sep 2, 2021
CISA Vulnrichment
Updated Aug 5, 2026
NVD
Status Analyzed
Modified Aug 6, 2026
Red Hat
Severity Important
Public date Sep 16, 2021