Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2021-40438— mod_proxy SSRF

Quick assessment

Affected
Apache Software Foundation Apache HTTP Server
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server存在代码问题漏洞,该漏洞是由于系统对用户的输入没有进行严格的过滤导致,攻击者可以构造恶意数据对目标服务器进行SSRF攻击。该漏洞可做为攻击目标服务器内网的跳板,以此对服务器所在内网进行端口扫描、攻击运行在内网的应用程序、下载内网资源等。

AI Predicted 9.1 Difficulty: Easy KEV · Ransomware EPSS 100.00% · P100

Public Exploits 1

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
Apache Software Foundation Apache HTTP Server Apache HTTP Server 2.4≤ 2.4.48 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2021-40438

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
mod_proxy SSRF
Source: CVE Program / CVE List V5
Vulnerability Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5
Vulnerability Title
Apache HTTP Server 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache HTTP Server是美国阿帕奇(Apache)基金会的一款开源网页服务器。该服务器具有快速、可靠且可通过简单的API进行扩充的特点。 Apache HTTP Server存在代码问题漏洞,该漏洞是由于系统对用户的输入没有进行严格的过滤导致,攻击者可以构造恶意数据对目标服务器进行SSRF攻击。该漏洞可做为攻击目标服务器内网的跳板,以此对服务器所在内网进行端口扫描、攻击运行在内网的应用程序、下载内网资源等。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache HTTP Server Apache HTTP Server 2.4 ~ 2.4.48 -

II. Public POCs for CVE-2021-40438

# POC Description Source Link Shenlong Link
1 None https://github.com/xiaojiangxl/CVE-2021-40438 POC Details
2 CVE-2021-40438 exploit PoC with Docker setup. https://github.com/sixpacksecurity/CVE-2021-40438 POC Details
3 None https://github.com/BabyTeam1024/CVE-2021-40438 POC Details
4 Dockerized Proof-of-Concept of CVE-2021-40438 in Apache 2.4.48. https://github.com/ericmann/apache-cve-poc POC Details
5 Sigma-Rule-for-CVE-2021-40438-Attack-Attemp https://github.com/pisut4152/Sigma-Rule-for-CVE-2021-40438-exploitation-attempt POC Details
6 Apache forward request CVE https://github.com/Kashkovsky/CVE-2021-40438 POC Details
7 check CVE-2021-40438 https://github.com/gassara-kys/CVE-2021-40438 POC Details
8 CVE-2021-40438 Apache <= 2.4.48 SSRF exploit https://github.com/sergiovks/CVE-2021-40438-Apache-2.4.48-SSRF-exploit POC Details
9 Apache <= 2.4.48 Mod_Proxy - Server-Side Request Forgery https://github.com/Cappricio-Securities/CVE-2021-40438 POC Details
10 Check Point Security Gateways RCE via CVE-2021-40438 https://github.com/element-security/check-point-gateways-rce POC Details
11 Check Point Security Gateways RCE via CVE-2021-40438 https://github.com/yakir2b/check-point-gateways-rce POC Details
12 Apache 2.4.48 and below contain an issue where uri-path can cause mod_proxy to forward the request to an origin server chosen by the remote user. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2021/CVE-2021-40438.yaml POC Details
13 None https://github.com/Threekiii/Awesome-POC/blob/master/%E4%B8%AD%E9%97%B4%E4%BB%B6%E6%BC%8F%E6%B4%9E/Apache%20HTTP%20Server%202.4.48%20mod_proxy%20SSRF%E6%BC%8F%E6%B4%9E%20CVE-2021-40438.md POC Details
14 None https://github.com/chaitin/xray-plugins/blob/main/poc/manual/apache-httpd-cve-2021-40438-ssrf.yml POC Details
15 https://github.com/vulhub/vulhub/blob/master/httpd/CVE-2021-40438/README.md POC Details
16 None https://github.com/n0m-d/CVE-2021-40438-POC POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2021-40438

请登录查看更多情报信息。

Vendor Advisories for CVE-2021-40438 (8)

Mailing List Discussions for CVE-2021-40438 (8)

Other References for CVE-2021-40438 (1)

Same Patch Batch · Apache Software Foundation · 2021-09-16 · 6 CVEs total

CVE-2021-41079 Apache Tomcat DoS with unexpected TLS packet
CVE-2021-39275 ap_escape_quotes buffer overflow
CVE-2021-39239 XML External Entity (XXE) vulnerability
CVE-2021-36160 mod_proxy_uwsgi out of bound read
CVE-2021-34798 NULL pointer dereference in httpd core

IV. Related Vulnerabilities

V. Comments for CVE-2021-40438

No comments yet


Leave a comment