Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Apache Proxy Paradox CVE-2021-40438

Summary

A black-box engagement: an outdated Apache 2.4.43 exposed CVE-2021-40438 (mod_proxy SSRF via Unix domain sockets), which testers weaponized to reach internal services and harvest cloud credentials.
Published
Collected

original ↗

Related coverage

back