HIGH · 8.2

CVE-2021-44224

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allo...

Vulnerability Description

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

CVSS Score

8.2

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
ApacheHttp Server>= 2.4.7, < 2.4.52
FedoraprojectFedora34
DebianDebian Linux10.0
TenableTenable.Sc>= 5.14.0, < 5.20.0
OracleCommunications Element Manager< 9.0
OracleCommunications Operations Monitor4.0
OracleCommunications Session Report Manager< 9.0
OracleCommunications Session Route Manager< 9.0
OracleHttp Server-
OracleInstantis Enterprisetrack17.1
AppleMac Os X10.15.7
AppleMacos< 10.15.7

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-44224?

CVE-2021-44224 is a vulnerability with a CVSS score of 8.2 (HIGH). A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allo...

How severe is CVE-2021-44224?

CVE-2021-44224 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-44224?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Http Server, Fedoraproject Fedora, Debian Debian Linux, Tenable Tenable.Sc, Oracle Communications Element Manager.