CVE-2021-40438
CVSS 3.1 Score 9.0 of 10 (high)
Details
Published Sep 16, 2021
Updated: Jul 24, 2024
CWE ID 918
Summary
CVE-2021-40438 is a vulnerability affecting Apache HTTP Server versions 2.4.48 and earlier. It allows a remote user to manipulate the request URI-path, causing mod_proxy to forward the request to an origin server of their choice instead of the intended one. This can lead to unintended exposure of sensitive data or unauthorized access. The impact of this issue can be significant, as it can bypass intended access controls and potentially result in serious security consequences.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Apache Software Foundation Apache HTTP Server
- Siemens SINEMA Remote Connect Server
- Tenable.sc
- Debian
- Fedora Operating System
Affected Vendors
- Apache Software Foundation
- Debian
- Fedora Project
- Tenable Network Security, Inc.
- BonqDAO