imPC@ndo IT

Tracker / CVE-2021-40438

CVE-2021-40438

Ransomware Critical 9.0

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Affected products and versions

apache http_server · … → 2.4.48
broadcom brocade_fabric_operating_system_firmware
debian debian_linux
f5 f5os · 1.1.0 → 1.1.4
f5 f5os · 1.2.0 → 1.2.1
fedoraproject fedora
netapp cloud_backup
netapp clustered_data_ontap
netapp storagegrid
oracle enterprise_manager_ops_center
oracle http_server
oracle instantis_enterprisetrack
oracle secure_global_desktop
oracle zfs_storage_appliance_kit
redhat enterprise_linux
redhat enterprise_linux_eus
redhat enterprise_linux_for_arm_64
redhat enterprise_linux_for_arm_64_eus
redhat enterprise_linux_for_ibm_z_systems
redhat enterprise_linux_for_ibm_z_systems_eus
redhat enterprise_linux_for_ibm_z_systems_eus_s390x
redhat enterprise_linux_for_power_big_endian
redhat enterprise_linux_for_power_little_endian
redhat enterprise_linux_for_power_little_endian_eus
redhat enterprise_linux_for_scientific_computing
redhat enterprise_linux_server
redhat enterprise_linux_server_aus
redhat enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions
redhat enterprise_linux_server_tus
redhat enterprise_linux_server_update_services_for_sap_solutions
redhat enterprise_linux_update_services_for_sap_solutions
redhat enterprise_linux_workstation
redhat jboss_core_services
redhat software_collections
resf rocky_linux
siemens ruggedcom_nms
siemens sinec_nms · … → 1.0.3
siemens sinema_remote_connect_server
siemens sinema_remote_connect_server · … → 3.1
siemens sinema_server
tenable tenable.sc · … → 5.19.1

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References