[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Server Side Request Forgery vulnerability in httpd

ID: oval:org.secpod.oval:def:76611Date: (C)2021-12-23   (M)2024-01-29
Class: VULNERABILITYFamily: unix




A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery).

Platform:
Red Hat Enterprise Linux 8
Product:
httpd
Reference:
CVE-2021-44224
CVE    1
CVE-2021-44224
CPE    2
cpe:/a:apache:http_server
cpe:/o:redhat:enterprise_linux:8

© SecPod Technologies