We are informing you of a security vulnerability found in Apache HTTP Server, a common web server software used to run many websites. The flaw impacts the server's mod_proxy feature, which routes web traffic to the correct backend servers that power your site.
Attackers can send a specially crafted web request to exploit this issue, tricking the server into forwarding that request to a server of the attacker's choosing, rather than the intended backend your website relies on. This vulnerability affects all Apache HTTP Server versions 2.4.48 and earlier.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438