A security flaw has been identified in Apache HTTP Server, the popular open-source web server software used to run many websites. The flaw impacts the server's proxy routing feature, which is designed to send incoming visitor requests to the correct backend server that hosts your site's content.
An attacker can send a specially crafted web request to exploit this flaw, which tricks the proxy feature into forwarding the request to a server of the attacker's choosing, rather than your intended backend server. This could allow unauthorized access to servers or services you did not mean to make accessible through your site, potentially leading to data leaks or access to systems you did not intend to expose.
This issue affects all versions of Apache HTTP Server 2.4.48 and all earlier versions of the software.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438