A security flaw has been identified in Apache HTTP Server, the widely used web server software that powers many websites, including those hosted on our platform. This issue affects all Apache HTTP Server versions 2.4.48 and older.
The vulnerability is triggered by a specially crafted web request sent to a server. It can trick the server's built-in request forwarding functionality into sending the request to a server chosen by the attacker, rather than the correct backend server your website is set up to use.
This could let attackers intercept or alter data traveling between your website and its backend services, redirect visitors to malicious or spoofed versions of your site, or disrupt your website's normal operation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438