CVE-2021-40438
Summary
| CVE | CVE-2021-40438 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-09-16 15:15:00 UTC |
| Updated | 2023-11-07 03:38:00 UTC |
| Description | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
Risk And Classification
EPSS: 0.944320000 probability, percentile 0.999850000 (date 2026-04-01)
CISA KEV: Listed on 2021-12-01; due 2021-12-15; ransomware use Unknown
Problem Types: CWE-918
CISA Known Exploited Vulnerability
| Vendor | Apache |
|---|---|
| Product | Apache |
| Name | Apache HTTP Server-Side Request Forgery (SSRF) |
| Required Action | Apply updates per vendor instructions. |
| Notes | https://nvd.nist.gov/vuln/detail/CVE-2021-40438 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 9.0 | All | All | All |
| Operating System | F5 | F5os | All | All | All | All |
| Operating System | F5 | F5os | All | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Netapp | Cloud Backup | - | All | All | All |
| Application | Netapp | Clustered Data Ontap | - | All | All | All |
| Application | Netapp | Storagegrid | - | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.4.0.0 | All | All | All |
| Application | Oracle | Http Server | 12.2.1.3.0 | All | All | All |
| Application | Oracle | Http Server | 12.2.1.4.0 | All | All | All |
| Application | Oracle | Instantis Enterprisetrack | 17.1 | All | All | All |
| Application | Oracle | Instantis Enterprisetrack | 17.2 | All | All | All |
| Application | Oracle | Instantis Enterprisetrack | 17.3 | All | All | All |
| Application | Oracle | Secure Global Desktop | 5.6 | All | All | All |
| Application | Oracle | Zfs Storage Appliance Kit | 8.8 | All | All | All |
| Application | Siemens | Sinec Nms | All | All | All | All |
| Application | Siemens | Sinema Server | 14.0 | - | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| September 2021 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Apache HTTPD: Multiple Vulnerabilities (GLSA 202208-20) — Gentoo security | GENTOO | security.gentoo.org | |
| [R1] Stand-alone Security Patch Available for Tenable.sc versions 5.16.0 to 5.19.1: Patch 202110.1 - Security Advisory | Tenable® | CONFIRM | www.tenable.com | |
| [httpd-users] 20211019 [users@httpd] Regarding CVE-2021-40438 | lists.apache.org | ||
| [SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info | lists.apache.org | ||
| [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info | lists.apache.org | ||
| [SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update Advisory - April 2022 | MISC | www.oracle.com | |
| Debian -- Security Information -- DSA-4982-1 apache2 | DEBIAN | www.debian.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [httpd-bugs] 20211008 [Bug 65616] CVE-2021-36160 regression | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| Oracle Critical Patch Update Advisory - January 2022 | MISC | www.oracle.com | |
| Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021 | CISCO | tools.cisco.com | |
| Pony Mail! | MLIST | lists.apache.org | |
| Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | MISC | httpd.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info | lists.apache.org | ||
| [SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 2776-1] apache2 security update | MLIST | lists.debian.org | |
| cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf | CONFIRM | cert-portal.siemens.com | |
| [httpd-users] 20211019 Re: [users@httpd] Regarding CVE-2021-40438 | lists.apache.org | ||
| Pony Mail! | MLIST | lists.apache.org | |
| [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info | lists.apache.org | ||
| [SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: The issue was discovered by the Apache HTTP security team while analysing CVE-2021-36160
Legacy QID Mappings
- 150461 Apache HTTP Server mod_proxy Server Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
- 159418 Oracle Enterprise Linux Security Update for httpd:2.4 (ELSA-2021-3816)
- 159419 Oracle Enterprise Linux Security Update for httpd (ELSA-2021-3856)
- 178815 Debian Security Update for apache2 (DLA 2776-1)
- 178819 Debian Security Update for apache2 (DSA 4982-1)
- 182834 Debian Security Update for apache2 (CVE-2021-40438)
- 198516 Ubuntu Security Notification for Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities (USN-5090-1)
- 239667 Red Hat Update for httpd24-httpd (RHSA-2021:3754)
- 239668 Red Hat Update for Red Hat JBoss Core Services Apache Hypertext Transfer Protocol Server (HTTP Server) 2.4.37 SP9 (RHSA-2021:3746)
- 239671 Red Hat Update for httpd:2.4 (RHSA-2021:3816)
- 239681 Red Hat Update for httpd (RHSA-2021:3856)
- 239686 Red Hat Update for httpd:2.4 (RHSA-2021:3837)
- 239687 Red Hat Update for httpd:2.4 (RHSA-2021:3836)
- 239871 Red Hat Update for httpd:2.4 (RHSA-2021:4537)
- 257120 CentOS Security Update for httpd (CESA-2021:3856)
- 281910 Fedora Security Update for Hypertext Transfer Protocol Daemon (HTTPd) (FEDORA-2021-dce7e7738e)
- 352857 Amazon Linux Security Advisory for httpd24: ALAS-2021-1543
- 352858 Amazon Linux Security Advisory for httpd: ALAS2-2021-1716
- 375988 Apache Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities
- 376041 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493841)
- 376256 Oracle Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities (CPUJAN2022)
- 376381 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493845,6493841)
- 376961 NetApp Clustered Data Open Network Technology for Appliance Products (ONTAP) Disclosure of Sensitive Information Vulnerability (NTAP-20211008-0004)
- 377000 Alibaba Cloud Linux Security Update for httpd (ALINUX2-SA-2021:0059)
- 377101 Alibaba Cloud Linux Security Update for httpd:2.4 (ALINUX3-SA-2021:0074)
- 378336 Zimbra Collaboration Suite (ZCS) Multiple Vulnerabilities
- 38856 Cisco TelePresence Video Communication Server (VCS) Apache Hypertext Transfer Protocol Server (HTTP Server) Vulnerability (cisco-sa-apache-httpd-2.4.49-VWL69sWQ)
- 500022 Alpine Linux Security Update for apache2
- 503713 Alpine Linux Security Update for apache2
- 591221 Siemens SINEC NMS and SINEMA Server Multiple Vulnerabilities (SSA-685781 V1.1)
- 671157 EulerOS Security Update for httpd (EulerOS-SA-2021-2803)
- 671166 EulerOS Security Update for httpd (EulerOS-SA-2021-2915)
- 671168 EulerOS Security Update for httpd (EulerOS-SA-2021-2923)
- 671190 EulerOS Security Update for httpd (EulerOS-SA-2021-2931)
- 671266 EulerOS Security Update for httpd (EulerOS-SA-2022-1167)
- 671293 EulerOS Security Update for httpd (EulerOS-SA-2022-1206)
- 671333 EulerOS Security Update for httpd (EulerOS-SA-2022-1225)
- 690025 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (882a38f9-17dd-11ec-b335-d4c9ef517024)
- 710595 Gentoo Linux Apache HTTPD Multiple Vulnerabilities (GLSA 202208-20)
- 730209 Apache Hypertext Transfer Protocol Server (HTTP Server) Multiple Vulnerabilities
- 731099 Hewlett Packard Enterprise (HPE) OneView Multiple Vulnerabilities (HPESBGN04586)
- 751198 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2021:3299-1)
- 751216 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2021:3335-1)
- 751279 OpenSUSE Security Update for apache2 (openSUSE-SU-2021:3522-1)
- 751314 OpenSUSE Security Update for apache2 (openSUSE-SU-2021:1438-1)
- 87468 Apache Hypertext Transfer Protocol (HTTP) Server mod_proxy Server-Side Request Forgery (SSRF) Vulnerability
- 87470 IBM Hypertext Transfer Protocol (HTTP) Server Multiple Vulnerabilities (6493841)
- 900331 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (5489)
- 901829 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (6487-1)
- 940297 AlmaLinux Security Update for httpd:2.4 (ALSA-2021:3816)
- 960440 Rocky Linux Security Update for httpd:2.4 (RLSA-2021:3816)