A security flaw has been identified in Apache HTTP Server, the common software used to process visitor requests for many websites. The issue affects the server's mod_proxy feature, which is designed to pass requests between the web server and the backend systems that power your site.
A specially crafted, malicious web request can trick this proxy feature into sending the request to a server selected by the person sending the attack, rather than your site's intended backend. This could allow bad actors to redirect visitors to fraudulent websites, or access sensitive information shared between visitors and your site.
This flaw impacts all versions of Apache HTTP Server 2.4.48 and older. If your website runs an affected version of this software, there is a risk that attackers could use this flaw to target your site and its visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438