A security issue has been identified in Apache HTTP Server, a common web server software used to run many hosted websites. The flaw impacts a proxy function built into the server software, and can be triggered by a specially crafted request path sent to the server.
When this flaw is exploited, it tricks the proxy function into forwarding the incoming request to a server selected by the sender of the malicious request, instead of the intended backend server configured for your website.
This issue affects all versions of Apache HTTP Server up to and including version 2.4.48.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438