PT-2021-5543 · Apache+11 · Apache Http Server+11

·

CVE-2021-44224

·

Published

2021-12-20

·

Updated

2026-06-29

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.7 through 2.4.51
Description The issue is related to a Server Side Request Forgery (SSRF) attack, which can be conducted by sending a specially crafted HTTP request. This can cause a crash due to a NULL pointer dereference or allow requests to be directed to a declared Unix Domain Socket endpoint for configurations that mix forward and reverse proxy declarations. The exploitation of this issue can allow a remote attacker to conduct an SSRF attack.
Recommendations For Apache HTTP Server versions 2.4.7 through 2.4.51, update to version 2.4.53 to resolve the issue. As a temporary workaround, consider disabling the forward proxy configuration (ProxyRequests off) until a patch is available. Restrict access to declared Unix Domain Socket endpoints to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:1915
ALT-PU-2021-3574
ALT-PU-2021-3635
ALT-PU-2021-3637
ALT-PU-2022-1211
AZL-7043
BDU:2021-06393
BIT-APACHE-2021-44224
CESA-2022_1915
CVE-2021-44224
DLA-2907-1
DSA-5035-1
MGASA-2021-0577
OESA-2021-1473
OPENSUSE-SU-2022:0091-1
OPENSUSE-SU-2022_0091-1
OPENSUSE-SU-2024:11695-1
RHSA-2022:1915
RHSA-2022:6753
RHSA-2022:7143
RHSA-2022_1915
RLSA-2022:1915
SUSE-SU-2022:0065-1
SUSE-SU-2022:0091-1
SUSE-SU-2022:0091-2
SUSE-SU-2022:0119-1
SUSE-SU-2022:0440-1
SUSE-SU-2026:2686-1
USN-5212-1
USN-5212-2

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Apple Macos
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu