A security flaw has been identified in Apache HTTP Server, the widely used open-source web server software that powers most websites online, including many hosted on our platform. This issue is officially tracked as CVE-2021-40438.
The flaw can be triggered by a specially crafted web request path. When exploited, it tricks the server's built-in request-forwarding feature into routing the user's request to a remote server selected by the attacker, rather than the intended backend server that hosts your website's content.
This issue impacts all installations of Apache HTTP Server running version 2.4.48 or earlier.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438