A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
References
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Configuration 4 (hide)
|
Configuration 5 (hide)
|
Configuration 6 (hide)
|
History
17 May 2022, 07:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
16 May 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Apr 2022, 00:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Apr 2022, 19:31
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
|
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/ - Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/ - Third Party Advisory | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/ - Mailing List, Third Party Advisory |
26 Mar 2022, 19:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
26 Mar 2022, 00:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Mar 2022, 06:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
19 Feb 2022, 04:42
Type | Values Removed | Values Added |
---|---|---|
First Time |
Debian debian Linux
Tenable tenable.sc Oracle Debian Oracle instantis Enterprisetrack Tenable |
|
References | (DEBIAN) https://www.debian.org/security/2022/dsa-5035 - Third Party Advisory | |
References | (CONFIRM) https://www.tenable.com/security/tns-2022-03 - Third Party Advisory | |
References | (CONFIRM) https://www.tenable.com/security/tns-2022-01 - Third Party Advisory | |
References | (MISC) https://www.oracle.com/security-alerts/cpujan2022.html - Patch, Third Party Advisory | |
CPE | cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:* cpe:2.3:a:tenable:tenable.sc:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:* |
07 Feb 2022, 16:16
Type | Values Removed | Values Added |
---|---|---|
References |
|
12 Jan 2022, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
06 Jan 2022, 01:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
05 Jan 2022, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
04 Jan 2022, 16:39
Type | Values Removed | Values Added |
---|---|---|
First Time |
Fedoraproject fedora
Fedoraproject |
|
CPE | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | |
References | (FEDORA) https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/ - Mailing List, Third Party Advisory | |
References | (CONFIRM) https://security.netapp.com/advisory/ntap-20211224-0001/ - Third Party Advisory |
24 Dec 2021, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
24 Dec 2021, 03:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Dec 2021, 18:36
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-476 | |
References | (MLIST) http://www.openwall.com/lists/oss-security/2021/12/20/3 - Mailing List, Third Party Advisory | |
References | (MISC) http://httpd.apache.org/security/vulnerabilities_24.html - Vendor Advisory | |
CPE | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : 6.4
v3 : 8.2 |
20 Dec 2021, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
20 Dec 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-12-20 12:15
Updated : 2022-05-17 07:15
NVD link : CVE-2021-44224
Mitre link : CVE-2021-44224
JSON object : View
Products Affected
fedoraproject
- fedora
apache
- http_server
tenable
- tenable.sc
debian
- debian_linux
oracle
- instantis_enterprisetrack
CWE
CWE-476
NULL Pointer Dereference