Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 82%
exploitation probability
82%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Affected
1 product (7 components)
Red Hat JBoss Enterprise Application Platform 6
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Fixed
6 products (149 components)
Red Hat Enterprise Linux AppStream (v. 8) · Red Hat Software Collections for RHEL Workstation(v. 7) · Red Hat JBoss Core Services on RHEL 8 · Red Hat JBoss Core Services on RHEL 7 Server · Red Hat Software Collections for RHEL(v. 7) · and others 1
Not affected
5 products (156 components) — because the vulnerable code is not present in the product
Red Hat JBoss Core Services on RHEL 8 · Red Hat JBoss Core Services on RHEL 7 Server · Red Hat Enterprise Linux 9 · Red Hat Enterprise Linux 7 · Red Hat Enterprise Linux 6
A crafted URI sent to httpd configured as a forward proxy (ProxyRequests on) can cause a crash (NULL pointer dereference) or, for configurations mixing forward and reverse proxy declarations, can allow for requests to be directed to a declared Unix Domain Socket endpoint (Server Side Request Forgery). This issue affects Apache HTTP Server 2.4.7 up to 2.4.51 (included).
Affected products
Apache Software Foundation · Apache HTTP ServerReferences
http://httpd.apache.org/security/vulnerabilities_24.htmlhttp://seclists.org/fulldisclosure/2022/May/33http://seclists.org/fulldisclosure/2022/May/35http://seclists.org/fulldisclosure/2022/May/38https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20211224-0001/https://support.apple.com/kb/HT213255https://support.apple.com/kb/HT213256