---
title: "CVE-2021-40438"
canonical: "https://kb.cynergy.app/space/MD/1124925452/CVE-2021-40438"
format: markdown
---
**Description**

CVE-2021-40438 is a vulnerability in the Apache HTTP Server that permits an attacker to send a malicious request, causing the server to initiate requests to arbitrary and potentially internal destinations. This type of attack is known as server-side request forgery (SSRF).

Exploiting this vulnerability allows an attacker to access internal server resources that are typically not accessible from the internet, such as intranet websites or internal network resources. Additionally, it can be used to bypass firewall rules or perform port scans on internal systems.

This vulnerability is located in the mod_proxy module of the Apache HTTP Server, which handles proxying requests from the server to other destinations. An attacker can exploit it by sending a specially crafted request with a malicious URL in the "Host" header, prompting the server to send a request to an internal destination specified in the URL.

Apache HTTP Server versions 2.4.1 to 2.4.46 are vulnerable to this issue.

According to the NIST description, a crafted request uri-path can cause mod_proxy to forward the request to an origin server chosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier versions.

**Published On**

09/16/2021

**Trending**

TRUE

**Threat Intelligence:**

CISA has added CVE-2021-40438 to its Known Exploited Vulnerabilities Catalog based on evidence that threat actors are actively exploiting the vulnerability. This vulnerability is a frequent attack vector for malicious cyber actors of all types and poses significant risks to the federal enterprise. 

[https://www.cisa.gov/known-exploited-vulnerabilities-catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog) 

**CWE**

<u>[CWE-120](http://cwe.mitre.org/data/definitions/120.html)</u>

**Exploit**

 [https://github.com/sergiovks/CVE-2021-40438-Apache-2.4.48-SSRF-exploit](https://github.com/sergiovks/CVE-2021-40438-Apache-2.4.48-SSRF-exploit) 

**Mitigation:**

Cynergy has an automated mitigation capability that requires integration with your WAF provider.

Once integrated, you can request “Protect with WAF”

This will move the exposed asset behind WAF protection

<span style="color: #97a0af">**Note: **</span><span style="color: #97a0af">Policies configuration should be defined separately</span> 

**Remediation:**

To address the CVE-2021-40438 vulnerability in the Apache HTTP Server, you should upgrade to a patched version. The version you need to upgrade to depends on your current Apache HTTP Server version.

The following versions include the fix for this vulnerability:

- 2.4.47
- 2.5.0-alpha

To upgrade, download the latest version from the Apache HTTP Server download page ([http://httpd.apache.org/download.cgi](http://httpd.apache.org/download.cgi) ). Follow the installation guide provided to complete the upgrade.

Alternatively, you can use your operating system's package manager to upgrade to a fixed version. Refer to your operating system or package manager documentation for detailed instructions on upgrading software packages.

Keep in mind that upgrading to a patched version of Apache HTTP Server alone will not fully mitigate the vulnerability. You must also ensure that any third-party modules or customizations are compatible with the new version.


**References:**  
CISCO: 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021

URL:[https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ](https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-apache-httpd-2.4.49-VWL69sWQ)

CONFIRM:[https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf)

CONFIRM:[https://security.netapp.com/advisory/ntap-20211008-0004/](https://security.netapp.com/advisory/ntap-20211008-0004/) 

URL:[https://security.netapp.com/advisory/ntap-20211008-0004/](https://security.netapp.com/advisory/ntap-20211008-0004/) 

CONFIRM:[https://www.tenable.com/security/tns-2021-17](https://www.tenable.com/security/tns-2021-17) 

URL:[https://www.tenable.com/security/tns-2021-17](https://www.tenable.com/security/tns-2021-17) 

DEBIAN:DSA-4982

URL:[https://www.debian.org/security/2021/dsa-4982](https://www.debian.org/security/2021/dsa-4982) 

FEDORA:FEDORA-2021-dce7e7738e

URL:[https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SPBR6WUYBJNACHKE65SPL7TJOHX7RHWD/) 

FEDORA:FEDORA-2021-e3f6dd670d

URL:[https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZNCYSR3BXT36FFF4XTCPL3HDQK4VP45R/) 

GENTOO:GLSA-202208-20

URL:[https://security.gentoo.org/glsa/202208-20](https://security.gentoo.org/glsa/202208-20) 

MISC:[https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) 

URL:[https://httpd.apache.org/security/vulnerabilities_24.html](https://httpd.apache.org/security/vulnerabilities_24.html) 

MISC:[https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html) 

URL:[https://www.oracle.com/security-alerts/cpuapr2022.html](https://www.oracle.com/security-alerts/cpuapr2022.html) 

MISC:[https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html) 

URL:[https://www.oracle.com/security-alerts/cpujan2022.html](https://www.oracle.com/security-alerts/cpujan2022.html) 

MLIST:[debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update

URL:[https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html](https://lists.debian.org/debian-lts-announce/2021/10/msg00001.html) 

MLIST:[httpd-bugs] 20211008 [Bug 65616] CVE-2021-36160 regression

URL:[https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37@%3Cbugs.httpd.apache.org%3E](https://lists.apache.org/thread.html/r2eb200ac1340f69aa22af61ab34780c531d110437910cb9c0ece3b37@%3Cbugs.httpd.apache.org%3E)

MLIST:[httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info

URL:[https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029@%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82c077663f9759c7df5a6656f925b3ee4f55fcd33c889ba7cd687029@%3Cusers.httpd.apache.org%3E)

MLIST:[httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info

URL:[https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c@%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r61fdbfc26ab170f4e6492ef3bd5197c20b862ce156e9d5a54d4b899c@%3Cusers.httpd.apache.org%3E)

MLIST:[httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info

URL:[https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697@%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r82838efc5fa6fc4c73986399c9b71573589f78b31846aff5bd9b1697@%3Cusers.httpd.apache.org%3E)

MLIST:[httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info

URL:[https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432@%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r3925e167d5eb1c75def3750c155d753064e1d34a143028bb32910432@%3Cusers.httpd.apache.org%3E)

MLIST:[httpd-users] 20211019 Re: [users@httpd] Regarding CVE-2021-40438

URL:[https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00@%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/rf6954e60b1c8e480678ce3d02f61b8a788997785652e9557a3265c00@%3Cusers.httpd.apache.org%3E)

MLIST:[httpd-users] 20211019 [users@httpd] Regarding CVE-2021-40438

URL:[https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a@%3Cusers.httpd.apache.org%3E](https://lists.apache.org/thread.html/r210807d0bb55f4aa6fbe1512be6bcc4dacd64e84940429fba329967a@%3Cusers.httpd.apache.org%3E)