CVE-2021-44224
20.12.2021, 12:15
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).Enginsight
Vendor | Product | Version |
---|---|---|
apache | http_server | 2.4.7 ≤ 𝑥 < 2.4.52 |
debian | debian_linux | 10.0 |
debian | debian_linux | 11.0 |
tenable | tenable.sc | 5.14.0 ≤ 𝑥 < 5.20.0 |
tenable | tenable.sc | 5.16.0 ≤ 𝑥 < 202201.1 |
oracle | communications_element_manager | 𝑥 < 9.0 |
oracle | communications_operations_monitor | 4.0 |
oracle | communications_operations_monitor | 4.3 |
oracle | communications_operations_monitor | 4.4 |
oracle | communications_operations_monitor | 5.0 |
oracle | communications_session_report_manager | 𝑥 < 9.0 |
oracle | communications_session_route_manager | 𝑥 < 9.0 |
oracle | http_server | - |
oracle | http_server | 12.2.1.3.0 |
oracle | http_server | 12.2.1.4.0 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
apple | mac_os_x | 10.15.7 |
apple | mac_os_x | 10.15.7:security_update_2020-001 |
apple | mac_os_x | 10.15.7:security_update_2021-001 |
apple | mac_os_x | 10.15.7:security_update_2021-002 |
apple | mac_os_x | 10.15.7:security_update_2021-003 |
apple | mac_os_x | 10.15.7:security_update_2021-004 |
apple | mac_os_x | 10.15.7:security_update_2021-005 |
apple | mac_os_x | 10.15.7:security_update_2021-006 |
apple | mac_os_x | 10.15.7:security_update_2021-007 |
apple | mac_os_x | 10.15.7:security_update_2021-008 |
apple | mac_os_x | 10.15.7:security_update_2022-001 |
apple | mac_os_x | 10.15.7:security_update_2022-002 |
apple | mac_os_x | 10.15.7:security_update_2022-003 |
apple | macos | 𝑥 < 10.15.7 |
apple | macos | 11.0 ≤ 𝑥 < 11.6.6 |
apple | macos | 12.0.0 ≤ 𝑥 < 12.4 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References