CVE-2021-44224

HIGH

Apache HTTP Server 2.4.7-2.4.51 - NULL Pointer Dereference and Server-Side Request Forgery via Forward Proxy

Title source: llm
STIX 2.1

Description

A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).

References (19)

Core 19
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2021/12/20/3
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2022/dsa-5035
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20211224-0001/
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2022-01
Third Party Advisory x_refsource_confirm
https://www.tenable.com/security/tns-2022-03
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213257
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213256
Third Party Advisory x_refsource_confirm
https://support.apple.com/kb/HT213255
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/May/33
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/May/35
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/May/38
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-20

Scores

CVSS v3 8.2
EPSS 0.0925
EPSS Percentile 92.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Details

CWE
CWE-476
Status published
Products (22)
apache/http_server 2.4.7 - 2.4.52
apple/mac_os_x 10.15.7 (13 CPE variants)
apple/macos < 10.15.7
debian/debian_linux 10.0
debian/debian_linux 11.0
fedoraproject/fedora 34
fedoraproject/fedora 35
fedoraproject/fedora 36
oracle/communications_element_manager < 9.0
oracle/communications_operations_monitor 4.0
... and 12 more
Published Dec 20, 2021
Tracked Since Feb 18, 2026