CVE-2021-40438
16.09.2021, 15:15
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
Vendor | Product | Version |
---|---|---|
resf | rocky_linux | 8.0 |
redhat | jboss_core_services | 1.0 |
redhat | software_collections | 1.0 |
redhat | enterprise_linux | 8.0 |
redhat | enterprise_linux_eus | 8.1 |
redhat | enterprise_linux_eus | 8.2 |
redhat | enterprise_linux_eus | 8.4 |
redhat | enterprise_linux_eus | 8.6 |
redhat | enterprise_linux_eus | 8.8 |
redhat | enterprise_linux_for_arm_64 | 8.0 |
redhat | enterprise_linux_for_arm_64_eus | 8.6 |
redhat | enterprise_linux_for_arm_64_eus | 8.8 |
redhat | enterprise_linux_for_ibm_z_systems | 7.0_s390x:_s390x |
redhat | enterprise_linux_for_ibm_z_systems | 8.0 |
redhat | enterprise_linux_for_ibm_z_systems_eus | 8.1 |
redhat | enterprise_linux_for_ibm_z_systems_eus | 8.4 |
redhat | enterprise_linux_for_ibm_z_systems_eus | 8.8 |
redhat | enterprise_linux_for_ibm_z_systems_eus_s390x | 8.2 |
redhat | enterprise_linux_for_power_big_endian | 7.0 |
redhat | enterprise_linux_for_power_little_endian | 7.0 |
redhat | enterprise_linux_for_power_little_endian | 8.0 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.1 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.2 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.4 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.6 |
redhat | enterprise_linux_for_power_little_endian_eus | 8.8 |
redhat | enterprise_linux_for_scientific_computing | 7.0 |
redhat | enterprise_linux_server | 7.0 |
redhat | enterprise_linux_server_aus | 7.2 |
redhat | enterprise_linux_server_aus | 7.3 |
redhat | enterprise_linux_server_aus | 7.4 |
redhat | enterprise_linux_server_aus | 7.6 |
redhat | enterprise_linux_server_aus | 7.7 |
redhat | enterprise_linux_server_aus | 8.2 |
redhat | enterprise_linux_server_aus | 8.4 |
redhat | enterprise_linux_server_aus | 8.6 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 7.6 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 7.7 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.1 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.2 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.4 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.6 |
redhat | enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions | 8.8 |
redhat | enterprise_linux_server_tus | 7.6 |
redhat | enterprise_linux_server_tus | 7.7 |
redhat | enterprise_linux_server_tus | 8.2 |
redhat | enterprise_linux_server_tus | 8.4 |
redhat | enterprise_linux_server_tus | 8.6 |
redhat | enterprise_linux_server_tus | 8.8 |
redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.6 |
redhat | enterprise_linux_server_update_services_for_sap_solutions | 7.7 |
redhat | enterprise_linux_update_services_for_sap_solutions | 8.1 |
redhat | enterprise_linux_update_services_for_sap_solutions | 8.2 |
redhat | enterprise_linux_update_services_for_sap_solutions | 8.4 |
redhat | enterprise_linux_update_services_for_sap_solutions | 8.6 |
redhat | enterprise_linux_update_services_for_sap_solutions | 8.8 |
redhat | enterprise_linux_workstation | 7.0 |
apache | http_server | 𝑥 ≤ 2.4.48 |
debian | debian_linux | 9.0 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
netapp | cloud_backup | - |
netapp | clustered_data_ontap | - |
netapp | storagegrid | - |
broadcom | brocade_fabric_operating_system_firmware | - |
f5 | f5os | 1.1.0 ≤ 𝑥 ≤ 1.1.4 |
f5 | f5os | 1.2.0 ≤ 𝑥 ≤ 1.2.1 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | http_server | 12.2.1.3.0 |
oracle | http_server | 12.2.1.4.0 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | secure_global_desktop | 5.6 |
oracle | zfs_storage_appliance_kit | 8.8 |
siemens | ruggedcom_nms | * |
siemens | sinec_nms | 𝑥 < 1.0.3 |
siemens | sinema_remote_connect_server | 𝑥 < 3.1 |
siemens | sinema_remote_connect_server | 3.2 |
siemens | sinema_server | 14.0 |
tenable | tenable.sc | 𝑥 ≤ 5.19.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References