QID 150461
Date Published: 2022-02-03
QID 150461: Apache HTTP Server mod_proxy Server Side Request Forgery (SSRF) Vulnerability (CVE-2021-40438)
The Apache HTTP Server, colloquially called Apache, is a free and open-source cross-platform web server software.
On affected versions of Apache HTTP Server, a SSRF vulnerability exists when a remote attacker sends a crafted request uri-path which causes "mod_proxy" to forward the request to a server chosen by the attacker.
Affected Versions:
Apache HTTP Server 2.4.48 and earlier
QID Detection Logic (Unauthenticated):
This QID sends a HTTP GET request and checks the response headers to confirm the vulnerable version of Apache HTTP Server running on the application.
Successful exploitation of this vulnerability could allow a remote attacker to send specially crafted HTTP requests and trick the web server to initiate requests to arbitrary systems.
- Apache HTTP Server Security Advisory -
httpd.apache.org/security/vulnerabilities_24.html
CVEs related to QID 150461
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Apache HTTP Server Security Advisory |
|