S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-40438 Scanner

CVE-2021-40438 scanner - Server-Side-Request-Forgery (SSRF) vulnerability in Apache HTTP Server

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2021-40438
9.0
CVSScritical
Exploitable remotely over the internet · no authentication required.

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache HTTP Serverby Apache Software Foundation
Apache HTTP Server 2.4
Updated Aug 21, 2026View on NVD →
Detail

Apache HTTP Server is a web server software designed to serve static and dynamic web pages. It is one of the most popular web servers in the world, used by millions of websites to deliver content to users across the globe. The software is open-source, free to use, and runs on various operating systems, including Windows, Linux, and Unix. Apache HTTP Server is renowned for its reliability, speed, and versatility, making it a top choice among web developers and organizations.

One of the recent vulnerabilities detected in Apache HTTP Server is the CVE-2021-40438. This vulnerability affects versions 2.4.48 and earlier and can be exploited by a skilled attacker to send a crafted request uri-path, causing mod_proxy to forward the request to an origin server chosen by the remote user. The attacker can use this vulnerability to compromise sensitive data, steal user credentials, or launch a distributed denial of service (DDoS) attack.

When exploited, this vulnerability can lead to serious consequences. Attackers can use the vulnerability to access confidential information, compromise the integrity of the web server, or cause service disruption to legitimate users. Exploiting the CVE-2021-40438 vulnerability can also allow attackers to gain unauthorized access to the server and further exploit other vulnerabilities on the same system.

Thanks to the pro features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. s4e.io provides comprehensive vulnerability scanning, reporting, and protection services, allowing individuals and organizations to stay informed and secure amidst the growing threat landscape. Don't let your digital assets fall prey to malicious attackers, join s4e.io today for peace of mind.

 

REFERENCES

Solution Advice

To protect against this vulnerability, Apache HTTP Server users and administrators are advised to take the following precautions:

  • Apply the latest software patches and security updates to your web server.
  • Configure mod_proxy to only allow requests from trusted sources.
  • Implement network-based access controls to limit access to your web server.
  • Monitor your web server logs for unusual activity, particularly requests containing unexpected or invalid uri-paths.
  • Consider using a web application firewall (WAF) to filter out malicious traffic from your web server.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.