9

CVE-2021-40438

Warnung

mod_proxy SSRF

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Resf ≫ Rocky Linux Version 8.0
Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Enterprise Linux Eus Version 8.1
Redhat ≫ Enterprise Linux Eus Version 8.2
Redhat ≫ Enterprise Linux Eus Version 8.4
Redhat ≫ Enterprise Linux Eus Version 8.6
Redhat ≫ Enterprise Linux Eus Version 8.8
Redhat ≫ Jboss Core Services Version 1.0
   Redhat ≫ Enterprise Linux Version 7.0
   Redhat ≫ Enterprise Linux Version 8.0
Redhat ≫ Software Collections Version 1.0
   Redhat ≫ Enterprise Linux Server Version 7.0
   Redhat ≫ Enterprise Linux Server Workstation Version 7.0
Apache ≫ HTTP Server Version <= 2.4.48
Fedoraproject ≫ Fedora Version 34
Fedoraproject ≫ Fedora Version 35
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Debian ≫ Debian Linux Version 11.0
Netapp ≫ Cloud Backup Version -
Netapp ≫ Storagegrid Version -
F5 ≫ F5os Version >= 1.1.0 <= 1.1.4
F5 ≫ F5os Version >= 1.2.0 <= 1.2.1
Oracle ≫ Enterprise Manager Ops Center Version 12.4.0.0
Oracle ≫ HTTP Server Version 12.2.1.3.0
Oracle ≫ HTTP Server Version 12.2.1.4.0
Oracle ≫ Secure Global Desktop Version 5.6
Siemens ≫ Sinec Nms Version < 1.0.3
Siemens ≫ Sinema Server Version 14.0 Update -
Tenable ≫ Tenable.Sc Version <= 5.19.1

01.12.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Apache HTTP Server-Side Request Forgery (SSRF)

Schwachstelle

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 100% 1
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CISA-ADP 9 2.2 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-918 Server-Side Request Forgery (SSRF)

The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

https://httpd.apache.org/security/vulnerabilities_24.html
Vendor Advisory
Release Notes
https://www.oracle.com/security-alerts/cpuapr2022.html
Patch
Third Party Advisory
https://www.oracle.com/security-alerts/cpujan2022.html
Patch
Third Party Advisory
https://security.gentoo.org/glsa/202208-20
Third Party Advisory
https://www.tenable.com/security/tns-2021-17
Third Party Advisory
https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html
Third Party Advisory
Mailing List
https://security.netapp.com/advisory/ntap-20211008-0004/
Third Party Advisory
https://www.debian.org/security/2021/dsa-4982
Third Party Advisory
Mailing List
https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E
Mailing List
https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E
Mailing List
https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E
Mailing List
https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E
Mailing List
https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E
Mailing List
https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E
Mailing List
https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E
Mailing List
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
Release Notes
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
Third Party Advisory
Broken Link
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-40438
US Government Resource