A security flaw has been found in Apache HTTP Server, the widely used software that routes visitor traffic to websites, that impacts all versions up to and including 2.4.48.
When a visitor sends a specially crafted request to a site running the affected server software, the flaw can trick the server's proxy feature (which forwards requests to backend servers as part of normal site operation) into sending that request to a server selected by the person sending the bad request, rather than the intended backend server your site is configured to use.
This could allow an attacker to access restricted resources, send malicious traffic through your server, or interact with backend systems in unintended ways that may compromise your site's security or disrupt its normal function.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438