Tracker / CVE-2021-40438
CVE-2021-40438
Ransomware Critical 9.0
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Affected products and versions
| apache | http_server · … → 2.4.48 |
|---|---|
| broadcom | brocade_fabric_operating_system_firmware |
| debian | debian_linux |
| f5 | f5os · 1.1.0 → 1.1.4 |
| f5 | f5os · 1.2.0 → 1.2.1 |
| fedoraproject | fedora |
| netapp | cloud_backup |
| netapp | clustered_data_ontap |
| netapp | storagegrid |
| oracle | enterprise_manager_ops_center |
| oracle | http_server |
| oracle | instantis_enterprisetrack |
| oracle | secure_global_desktop |
| oracle | zfs_storage_appliance_kit |
| redhat | enterprise_linux |
| redhat | enterprise_linux_eus |
| redhat | enterprise_linux_for_arm_64 |
| redhat | enterprise_linux_for_arm_64_eus |
| redhat | enterprise_linux_for_ibm_z_systems |
| redhat | enterprise_linux_for_ibm_z_systems_eus |
| redhat | enterprise_linux_for_ibm_z_systems_eus_s390x |
| redhat | enterprise_linux_for_power_big_endian |
| redhat | enterprise_linux_for_power_little_endian |
| redhat | enterprise_linux_for_power_little_endian_eus |
| redhat | enterprise_linux_for_scientific_computing |
| redhat | enterprise_linux_server |
| redhat | enterprise_linux_server_aus |
| redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions |
| redhat | enterprise_linux_server_tus |
| redhat | enterprise_linux_server_update_services_for_sap_solutions |
| redhat | enterprise_linux_update_services_for_sap_solutions |
| redhat | enterprise_linux_workstation |
| redhat | jboss_core_services |
| redhat | software_collections |
| resf | rocky_linux |
| siemens | ruggedcom_nms |
| siemens | sinec_nms · … → 1.0.3 |
| siemens | sinema_remote_connect_server |
| siemens | sinema_remote_connect_server · … → 3.1 |
| siemens | sinema_server |
| tenable | tenable.sc · … → 5.19.1 |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.