Apache Proxy Paradox CVE-2021-40438
labs.cognisys.group | vulnerability | CVE-2021-40438 | #cloud | #pentesting | #apache | #ssrf | #cve-2021-40438 | #mod-proxy | #cloud-credentials
Summary
A black-box engagement: an outdated Apache 2.4.43 exposed CVE-2021-40438 (mod_proxy SSRF via Unix domain sockets), which testers weaponized to reach internal services and harvest cloud credentials.
- Published
- Collected
Skip to content