
Requesting a uri-path can cause mod_proxy to forward the request to an origin server selected by a remote user. This issue affects Apache HTTP Server 2.4.48 and earlier versions.
Attackers can exploit this vulnerability by crafting a request with a uri-path, which causes mod_proxy to forward the request to an origin server chosen by the attacker. The mod_proxy component of Apache HTTP Server is designed to implement proxy/gateway functionality for Apache HTTP Server.
Apache <= 2.4.48 - Mod_Proxy SSRF
This vulnerability was disclosed as part of the security update bulletin for Apache HTTP Server 2.4.49, which fixed the issue. Affected systems should immediately upgrade to the latest version 2.4.49.