CVE-2021-40438 - log back

CVE-2021-40438 edited at 16 Sep 2021 16:28:10
Severity
- Unknown
+ High
Remote
- Unknown
+ Remote
Type
- Unknown
+ Url request injection
Description
+ In Apache HTTP Server before version 2.4.49, a crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.
References
+ https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2021-40438
Notes
CVE-2021-40438 created at 16 Sep 2021 16:22:21