A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
| Vendor | Product | Versions | Fixed In |
|---|---|---|---|
| apache | http_server | 2.4.7 - 2.4.52 | - |
| fedoraproject | fedora | - | - |
| fedoraproject | fedora | - |
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
37
Affected Products
38
References
apache / http_server
| - |
| fedoraproject | fedora | - | - |
| debian | debian_linux | - | - |
| debian | debian_linux | - | - |
| tenable | tenable.sc | 5.14.0 - 5.20.0 | - |
| tenable | tenable.sc | 5.16.0 - 202201.1 | - |
| oracle | communications_element_manager | 9.0 | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_operations_monitor | - | - |
| oracle | communications_session_report_manager | 9.0 | - |
| oracle | communications_session_route_manager | 9.0 | - |
| oracle | http_server | - | - |
| oracle | http_server | - | - |
| oracle | http_server | - | - |
| oracle | instantis_enterprisetrack | - | - |
| oracle | instantis_enterprisetrack | - | - |
| oracle | instantis_enterprisetrack | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | mac_os_x | - | - |
| apple | macos | 10.15.7 | - |
| apple | macos | 11.0 - 11.6.6 | - |
| apple | macos | 12.0.0 - 12.4 | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
Exploitability
Impact