A security flaw has been found in Apache HTTP Server, the common software that powers many websites including those hosted on our platform. The issue affects the mod_proxy component, which is designed to pass web requests between your site and its backend servers. A specially crafted, malicious web request can trick this component into sending the request to a server selected by an attacker, rather than your intended backend. This could allow bad actors to access private data tied to your site, redirect your visitors to harmful or fraudulent pages, or intercept and alter traffic meant for your website without your knowledge. This flaw impacts all versions of Apache HTTP Server 2.4.48 and earlier.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438