mod_proxy SSRF
Published Sep 16, 2021 ·Due Dec 15, 2021
9.0
CRITICALCVSS 3.1
EPSS 100.00%
Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Affected products
-
- Version Apache HTTP Server 2.4StatusaffectedConstraints<=2.4.48
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | n/a |
|
Configuration 1
- 8.0
Configuration 2
- 8.0
- 8.1
- 8.2
- 8.4
- 8.6
- 8.8
- 8.0
- 8.6
- 8.8
- 7.0_s390x
- 8.0
- 8.1
- 8.4
- 8.8
- 8.2
- 7.0
- 7.0
- 8.0
- 8.1
- 8.2
- 8.4
- 8.6
- 8.8
- 7.0
- 7.0
- 7.2
- 7.3
- 7.4
- 7.6
- 7.7
- 8.2
- 8.4
- 8.6
- 7.6
- 7.7
- 8.1
- 8.2
- 8.4
- 8.6
- 8.8
- 7.6
- 7.7
- 8.2
- 8.4
- 8.6
- 8.8
- 7.6
- 7.7
- 8.1
- 8.2
- 8.4
- 8.6
- 8.8
- 7.0
Configuration 3
- 1.0
Running on/with
- 7.0
- 8.0
Configuration 4
- 1.0
Running on/with
- 7.0
- 7.0
Configuration 5
- ≤ 2.4.48
Configuration 6
- 34
- 35
Configuration 7
- 9.0
- 10.0
- 11.0
Configuration 8
- n/a
- n/a
- n/a
- n/a
Configuration 10
- 12.4.0.0
- 12.2.1.3.0
- 12.2.1.4.0
- 17.1
- 17.2
- 17.3
- 5.6
- 8.8
Configuration 11
- n/a
- < 1.0.3
- < 3.1
- 3.2
- 14.0
Configuration 12
- ≤ 5.19.1
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.37-76.el8jbcs
Fixed · RHSA-2021:3746
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_cluster-native-0:1.3.16-7.Final_redhat_2.el8jbcs
Fixed · RHSA-2021:3746
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_http2-0:1.15.7-19.el8jbcs
Fixed · RHSA-2021:3746
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_jk-0:1.2.48-18.redhat_1.el8jbcs
Fixed · RHSA-2021:3746
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_md-1:2.0.8-38.el8jbcs
Fixed · RHSA-2021:3746
JBoss Core Services for RHEL 8
jbcs-httpd24-mod_security-0:2.9.2-65.GA.el8jbcs
Fixed · RHSA-2021:3746
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.37-76.jbcs.el7
Fixed · RHSA-2021:3746
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_cluster-native-0:1.3.16-7.Final_redhat_2.jbcs.el7
Fixed · RHSA-2021:3746
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_http2-0:1.15.7-19.jbcs.el7
Fixed · RHSA-2021:3746
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_jk-0:1.2.48-18.redhat_1.jbcs.el7
Fixed · RHSA-2021:3746
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_md-1:2.0.8-38.jbcs.el7
Fixed · RHSA-2021:3746
JBoss Core Services on RHEL 7
jbcs-httpd24-mod_security-0:2.9.2-65.GA.jbcs.el7
Fixed · RHSA-2021:3746
Red Hat Enterprise Linux 7
httpd-0:2.4.6-97.el7_9.1
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.2 Advanced Update Support
httpd-0:2.4.6-40.el7_2.7
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.3 Advanced Update Support
httpd-0:2.4.6-45.el7_3.6
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.4 Advanced Update Support
httpd-0:2.4.6-67.el7_4.7
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.6 Advanced Update Support
httpd-0:2.4.6-89.el7_6.2
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.6 Telco Extended Update Support
httpd-0:2.4.6-89.el7_6.2
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions
httpd-0:2.4.6-89.el7_6.2
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.7 Advanced Update Support
httpd-0:2.4.6-90.el7_7.1
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.7 Telco Extended Update Support
httpd-0:2.4.6-90.el7_7.1
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions
httpd-0:2.4.6-90.el7_7.1
Fixed · RHSA-2021:3856
Red Hat Enterprise Linux 8
httpd:2.4-8040020211008164252.522a0ee4
Fixed · RHSA-2021:3816
Red Hat Enterprise Linux 8.1 Extended Update Support
httpd:2.4-8010020211008125020.c27ad7f8
Fixed · RHSA-2021:3837
Red Hat Enterprise Linux 8.2 Extended Update Support
httpd:2.4-8020020211008164029.4cda2c84
Fixed · RHSA-2021:3836
Red Hat JBoss Core Services
n/a
Fixed · RHSA-2021:3745
Red Hat Software Collections for Red Hat Enterprise Linux 7
httpd24-httpd-0:2.4.34-22.el7.1
Fixed · RHSA-2021:3754
Red Hat Enterprise Linux 6
httpd
Not affected
Red Hat Enterprise Linux 9
httpd
Not affected
Red Hat JBoss Enterprise Application Platform 6
httpd
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.37-76.el8jbcs | Fixed | RHSA-2021:3746 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_cluster-native-0:1.3.16-7.Final_redhat_2.el8jbcs | Fixed | RHSA-2021:3746 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_http2-0:1.15.7-19.el8jbcs | Fixed | RHSA-2021:3746 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_jk-0:1.2.48-18.redhat_1.el8jbcs | Fixed | RHSA-2021:3746 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_md-1:2.0.8-38.el8jbcs | Fixed | RHSA-2021:3746 |
| JBoss Core Services for RHEL 8 | jbcs-httpd24-mod_security-0:2.9.2-65.GA.el8jbcs | Fixed | RHSA-2021:3746 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.37-76.jbcs.el7 | Fixed | RHSA-2021:3746 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_cluster-native-0:1.3.16-7.Final_redhat_2.jbcs.el7 | Fixed | RHSA-2021:3746 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_http2-0:1.15.7-19.jbcs.el7 | Fixed | RHSA-2021:3746 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_jk-0:1.2.48-18.redhat_1.jbcs.el7 | Fixed | RHSA-2021:3746 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_md-1:2.0.8-38.jbcs.el7 | Fixed | RHSA-2021:3746 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-mod_security-0:2.9.2-65.GA.jbcs.el7 | Fixed | RHSA-2021:3746 |
| Red Hat Enterprise Linux 7 | httpd-0:2.4.6-97.el7_9.1 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | httpd-0:2.4.6-40.el7_2.7 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | httpd-0:2.4.6-45.el7_3.6 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | httpd-0:2.4.6-67.el7_4.7 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.6 Advanced Update Support | httpd-0:2.4.6-89.el7_6.2 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.6 Telco Extended Update Support | httpd-0:2.4.6-89.el7_6.2 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.6 Update Services for SAP Solutions | httpd-0:2.4.6-89.el7_6.2 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.7 Advanced Update Support | httpd-0:2.4.6-90.el7_7.1 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.7 Telco Extended Update Support | httpd-0:2.4.6-90.el7_7.1 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 7.7 Update Services for SAP Solutions | httpd-0:2.4.6-90.el7_7.1 | Fixed | RHSA-2021:3856 |
| Red Hat Enterprise Linux 8 | httpd:2.4-8040020211008164252.522a0ee4 | Fixed | RHSA-2021:3816 |
| Red Hat Enterprise Linux 8.1 Extended Update Support | httpd:2.4-8010020211008125020.c27ad7f8 | Fixed | RHSA-2021:3837 |
| Red Hat Enterprise Linux 8.2 Extended Update Support | httpd:2.4-8020020211008164029.4cda2c84 | Fixed | RHSA-2021:3836 |
| Red Hat JBoss Core Services | n/a | Fixed | RHSA-2021:3745 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | httpd24-httpd-0:2.4.34-22.el7.1 | Fixed | RHSA-2021:3754 |
| Red Hat Enterprise Linux 6 | httpd | Not affected | n/a |
| Red Hat Enterprise Linux 9 | httpd | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | httpd | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Impact of the flaw set to Important because the actions an attacker can do varies a lot based on the kind of infrastructure in place, the kind of internal services and resources, and the available endpoints on those services. The attacker should also perform some kind of target-specific reconnaissance in order to find out all the above information. The version of httpd as shipped in Red Hat Enterprise Linux 7 is affected by this flaw even if the upstream code was not, because the Unix Domain Socket support required to trigger the flaw was backported. The version of httpd as shipped in Red hat Enterprise Linux 6 is not affected by this flaw because there is no support for Unix Domain Socket. The flaw can be triggered only if mod_proxy is in use (e.g. ProxyPass, ReverseProxy is used in the httpd configuration files).
Red Hat mitigation
Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update the affected package as soon as possible.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
AV:N/AC:M/Au:N/C:P/I:P/A:P
Date Added
Dec 1, 2021
Patch Due
Dec 15, 2021
Required Action
Apply updates per vendor instructions.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Aug 5, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (40 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 100.00% (0.99999) | 100.00th | v5 (v2026.06.15) |
| Jun 15, 2026 | 100.00% (0.99999) | 100.00th | v5 (v2026.06.15) |
| Mar 17, 2025 | 94.44% (0.94440) | 99.99th | v4 (v2025.03.14) |
| Dec 12, 2024 | 96.70% (0.96700) | 99.71th | v3 (v2023.03.01) |
| Jun 19, 2024 | 97.06% (0.97057) | 99.77th | v3 (v2023.03.01) |
| Jun 1, 2024 | 97.44% (0.97435) | 99.94th | v3 (v2023.03.01) |
| Apr 22, 2024 | 97.45% (0.97446) | 99.95th | v3 (v2023.03.01) |
| Mar 27, 2024 | 97.41% (0.97406) | 99.92th | v3 (v2023.03.01) |
| Mar 14, 2024 | 97.37% (0.97372) | 99.89th | v3 (v2023.03.01) |
| Feb 29, 2024 | 97.33% (0.97332) | 99.87th | v3 (v2023.03.01) |
| Feb 7, 2024 | 97.36% (0.97365) | 99.88th | v3 (v2023.03.01) |
| Jan 6, 2024 | 97.12% (0.97120) | 99.74th | v3 (v2023.03.01) |
| Dec 21, 2023 | 97.14% (0.97139) | 99.75th | v3 (v2023.03.01) |
| Nov 24, 2023 | 97.18% (0.97178) | 99.76th | v3 (v2023.03.01) |
| Nov 8, 2023 | 97.20% (0.97200) | 99.78th | v3 (v2023.03.01) |
| Oct 27, 2023 | 97.28% (0.97279) | 99.81th | v3 (v2023.03.01) |
| Oct 13, 2023 | 97.31% (0.97309) | 99.82th | v3 (v2023.03.01) |
| Sep 22, 2023 | 97.29% (0.97287) | 99.80th | v3 (v2023.03.01) |
| Sep 13, 2023 | 97.52% (0.97515) | 99.98th | v3 (v2023.03.01) |
| Aug 16, 2023 | 97.52% (0.97523) | 99.98th | v3 (v2023.03.01) |
| Jun 6, 2023 | 97.54% (0.97540) | 99.99th | v3 (v2023.03.01) |
| May 8, 2023 | 97.52% (0.97522) | 99.97th | v3 (v2023.03.01) |
| Mar 27, 2023 | 97.51% (0.97512) | 99.97th | v3 (v2023.03.01) |
| Mar 7, 2023 | 97.53% (0.97528) | 99.98th | v3 (v2023.03.01) |
| Mar 6, 2023 | 97.22% (0.97224) | 100.00th | v2 (v2022.01.01) |
| Feb 4, 2022 | 97.22% (0.97224) | 100.00th | v2 (v2022.01.01) |
| Feb 3, 2022 | 36.56% (0.36558) | 98.05th | v1 |
| Nov 25, 2021 | 36.56% (0.36558) | 99.14th | v1 |
| Oct 20, 2021 | 35.06% (0.35064) | 98.92th | v1 |
| Oct 19, 2021 | 31.86% (0.31856) | 98.65th | v1 |
| Oct 18, 2021 | 30.13% (0.30132) | 98.50th | v1 |
| Oct 11, 2021 | 8.77% (0.08769) | 93.79th | v1 |
| Oct 9, 2021 | 28.32% (0.28320) | 98.36th | v1 |
| Oct 5, 2021 | 24.40% (0.24402) | 98.07th | v1 |
| Oct 3, 2021 | 6.71% (0.06711) | 91.13th | v1 |
| Sep 28, 2021 | 6.01% (0.06006) | 89.60th | v1 |
| Sep 25, 2021 | 2.08% (0.02080) | 77.39th | v1 |
| Sep 24, 2021 | 1.82% (0.01823) | 74.78th | v1 |
| Sep 21, 2021 | 0.78% (0.00785) | 52.35th | v1 |
| Sep 17, 2021 | 0.52% (0.00523) | 32.39th | v1 |
References (25)
- https://access.redhat.com/security/cve/CVE-2021-40438 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2005117 Issue Tracking
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf x_refsource_CONFIRMThird Party Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html x_refsource_MISCRelease NotesVendor Advisory
- https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E mailing-listx_refsource_MLISTMailing List
- https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/ vendor-advisoryx_refsource_FEDORARelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/ vendor-advisoryx_refsource_FEDORARelease Notes
- https://nvd.nist.gov/vuln/detail/CVE-2021-40438
- https://security.gentoo.org/glsa/202208-20 vendor-advisoryx_refsource_GENTOOThird Party Advisory
- https://security.netapp.com/advisory/ntap-20211008-0004/ x_refsource_CONFIRMThird Party Advisory
- https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ vendor-advisoryx_refsource_CISCOBroken LinkThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40438 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2021-40438
- https://www.debian.org/security/2021/dsa-4982 vendor-advisoryx_refsource_DEBIANMailing ListThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.tenable.com/security/tns-2021-17 x_refsource_CONFIRMThird Party Advisory
Change history (0)
No recorded changes yet.