VulnerabilityAnalyzed
CVE-2021-44790
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts).
CRITICAL 9.8EPSS 96.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 96.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 96.84% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-787
- Affected
- apache/http server · fedoraproject/fedora · debian/debian linux · tenable/tenable.sc · netapp/cloud backup · oracle/communications element manager · oracle/communications operations monitor · oracle/communications session report manager · oracle/communications session route manager · oracle/http server · oracle/instantis enterprisetrack · oracle/zfs storage appliance kit · apple/mac os x · apple/macos
- Source
- security@apache.org
References
- http://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- http://packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.htmlExploit
- http://seclists.org/fulldisclosure/2022/May/33Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/20/4Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/Third Party Advisory
- https://security.gentoo.org/glsa/202208-20Third Party Advisory
- https://security.netapp.com/advisory/ntap-20211224-0001/Third Party Advisory
- https://support.apple.com/kb/HT213255Third Party Advisory
- https://support.apple.com/kb/HT213256Third Party Advisory
- https://support.apple.com/kb/HT213257Third Party Advisory
- https://www.debian.org/security/2022/dsa-5035Third Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.htmlPatch, Third Party Advisory
- https://www.tenable.com/security/tns-2022-01Third Party Advisory
- https://www.tenable.com/security/tns-2022-03Third Party Advisory
- http://httpd.apache.org/security/vulnerabilities_24.htmlVendor Advisory
- http://packetstormsecurity.com/files/171631/Apache-2.4.x-Buffer-Overflow.htmlExploit
- http://seclists.org/fulldisclosure/2022/May/33Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/35Mailing List, Third Party Advisory
- http://seclists.org/fulldisclosure/2022/May/38Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/12/20/4Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFSWOH4X77CV7AH7C4RMHUBDWKQDL4YH/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.