PT-2021-5543 · Apache+11 · Apache Http Server+11
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.7 through 2.4.51
Description
The issue is related to a Server Side Request Forgery (SSRF) attack, which can be conducted by sending a specially crafted HTTP request. This can cause a crash due to a NULL pointer dereference or allow requests to be directed to a declared Unix Domain Socket endpoint for configurations that mix forward and reverse proxy declarations. The exploitation of this issue can allow a remote attacker to conduct an SSRF attack.
Recommendations
For Apache HTTP Server versions 2.4.7 through 2.4.51, update to version 2.4.53 to resolve the issue.
As a temporary workaround, consider disabling the forward proxy configuration (ProxyRequests off) until a patch is available.
Restrict access to declared Unix Domain Socket endpoints to minimize the risk of exploitation.
Exploit
Fix
DoS
NULL Pointer Dereference
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu