Description
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected products
- apache / http_server2.4.48
- Apache Software Foundation / Apache HTTP ServerApache HTTP Server 2.4 – 2.4.48
- Broadcom / brocade_fabric_operating_system_firmware
- debian / debian_linux10.0 – 10.0
- debian / debian_linux9.0 – 9.0
- debian / debian_linux11.0 – 11.0
- F5 / f5os1.1.0 – 1.1.4
- fedoraproject / fedora34 – 34
- fedoraproject / fedora35 – 35
- NETAPP / cloud_backup
- NETAPP / Clustered Data ONTAP
- NETAPP / StorageGRID
- oracle / enterprise_manager_ops_center12.4.0.0 – 12.4.0.0
- oracle / http_server12.2.1.4.0 – 12.2.1.4.0
- oracle / http_server12.2.1.3.0 – 12.2.1.3.0
- oracle / instantis_enterprisetrack17.3 – 17.3
- oracle / instantis_enterprisetrack17.1 – 17.1
- oracle / instantis_enterprisetrack17.2 – 17.2
- oracle / secure_global_desktop5.6 – 5.6
- oracle / zfs_storage_appliance_kit8.8 – 8.8
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux_eus8.6 – 8.6
- RedHat / enterprise_linux_eus8.8 – 8.8
- RedHat / enterprise_linux_eus8.4 – 8.4
- RedHat / enterprise_linux_eus8.2 – 8.2
- RedHat / enterprise_linux_eus8.1 – 8.1
- RedHat / enterprise_linux_for_arm_648.0 – 8.0
- RedHat / enterprise_linux_for_arm_64_eus8.8 – 8.8
- RedHat / enterprise_linux_for_arm_64_eus8.6 – 8.6
- RedHat / enterprise_linux_for_ibm_z_systems7.0_s390x – 7.0_s390x
- RedHat / enterprise_linux_for_ibm_z_systems8.0 – 8.0
- RedHat / enterprise_linux_for_ibm_z_systems_eus8.8 – 8.8
- RedHat / enterprise_linux_for_ibm_z_systems_eus8.4 – 8.4
- RedHat / enterprise_linux_for_ibm_z_systems_eus8.1 – 8.1
- RedHat / enterprise_linux_for_ibm_z_systems_eus_s390x8.2 – 8.2
- RedHat / enterprise_linux_for_power_big_endian7.0 – 7.0
- RedHat / enterprise_linux_for_power_little_endian7.0 – 7.0
- RedHat / enterprise_linux_for_power_little_endian8.0 – 8.0
- RedHat / enterprise_linux_for_power_little_endian_eus8.1 – 8.1
- RedHat / enterprise_linux_for_power_little_endian_eus8.4 – 8.4
- RedHat / enterprise_linux_for_power_little_endian_eus8.6 – 8.6
- RedHat / enterprise_linux_for_power_little_endian_eus8.8 – 8.8
- RedHat / enterprise_linux_for_power_little_endian_eus8.2 – 8.2
- RedHat / enterprise_linux_for_scientific_computing7.0 – 7.0
- RedHat / enterprise_linux_server7.0 – 7.0
- RedHat / enterprise_linux_server_aus8.2 – 8.2
- RedHat / enterprise_linux_server_aus7.7 – 7.7
- RedHat / enterprise_linux_server_aus8.4 – 8.4
- RedHat / enterprise_linux_server_aus8.6 – 8.6
- RedHat / enterprise_linux_server_aus7.3 – 7.3
- RedHat / enterprise_linux_server_aus7.2 – 7.2
- RedHat / enterprise_linux_server_aus7.4 – 7.4
- RedHat / enterprise_linux_server_aus7.6 – 7.6
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.1 – 8.1
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.4 – 8.4
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.6 – 8.6
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.8 – 8.8
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions7.7 – 7.7
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions7.6 – 7.6
- RedHat / enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions8.2 – 8.2
- RedHat / enterprise_linux_server_tus7.6 – 7.6
- RedHat / enterprise_linux_server_tus8.8 – 8.8
- RedHat / enterprise_linux_server_tus8.6 – 8.6
- RedHat / enterprise_linux_server_tus8.4 – 8.4
- RedHat / enterprise_linux_server_tus8.2 – 8.2
- RedHat / enterprise_linux_server_tus7.7 – 7.7
- RedHat / enterprise_linux_server_update_services_for_sap_solutions7.7 – 7.7
- RedHat / enterprise_linux_server_update_services_for_sap_solutions7.6 – 7.6
- RedHat / enterprise_linux_update_services_for_sap_solutions8.1 – 8.1
- RedHat / enterprise_linux_update_services_for_sap_solutions8.2 – 8.2
- RedHat / enterprise_linux_update_services_for_sap_solutions8.4 – 8.4
- RedHat / enterprise_linux_update_services_for_sap_solutions8.6 – 8.6
- RedHat / enterprise_linux_update_services_for_sap_solutions8.8 – 8.8
- RedHat / enterprise_linux_workstation7.0 – 7.0
- RedHat / jboss_core_services1.0 – 1.0
- RedHat / software_collections1.0 – 1.0
- resf / rocky_linux8.0 – 8.0
- Siemens / ruggedcom_nms
- Siemens / SINEC NMS1.0.3
- Siemens / SINEMA Remote Connect Server3.1
- Siemens / SINEMA Remote Connect Server3.2 – 3.2
- Siemens / SINEMA Server14.0 – 14.0
- tenable / tenable.sc5.19.1
Exploits & proofs of concept
- nucleiApache <= 2.4.48 Mod_Proxy - Server-Side Request Forgeryby pdteam
References
- MISChttps://httpd.apache.org/security/vulnerabilities_24.html
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/
- MAILING_LISThttps://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697%40%3Cusers.httpd.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029%40%3Cusers.httpd.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432%40%3Cusers.httpd.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c%40%3Cusers.httpd.apache.org%3E
- MAILING_LISThttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2021/10/msg00001.html
- MAILING_LISThttps://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37%40%3Cbugs.httpd.apache.org%3E
- VENDOR_ADVISORYhttps://www.debian.org/security/2021/dsa-4982
- MAILING_LISThttps://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a%40%3Cusers.httpd.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00%40%3Cusers.httpd.apache.org%3E
- VENDOR_ADVISORYhttps://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2022.html
- MISChttps://www.tenable.com/security/tns-2021-17
- MISChttps://security.netapp.com/advisory/ntap-20211008-0004/
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuapr2022.html
- MISChttps://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- MISChttps://security.gentoo.org/glsa/202208-20
Updated 20m ago · 8 sources