ALT-PU-2021-2866-1
Closed vulnerabilities
BDU:2021-04216
Уязвимость модуля mod_proxy httpd-демона веб-сервера Apache HTTP Server, позволяющая нарушителю отправить скрытый HTTP-запрос (атака типа HTTP Request Smuggling)
BDU:2021-04820
Уязвимость модуля mod_proxy веб-сервера Apache HTTP Server, позволяющая нарушителю осуществить SSRF-атаку
BDU:2021-05873
Уязвимость веб-сервера Apache HTTP Server, связанная с разыменованием нулевого указателя, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-06099
Уязвимость функции mod_proxy_uwsgi веб-сервера Apache HTTP Server, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2022-00203
Уязвимость функции ap_escape_quotes() веб-сервера Apache HTTP Server, связанная с записью за границами буфера в памяти, позволяющая нарушителю получить доступ к конфиденциальным данным, нарушить их целостность, а также вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-33193
A crafted method sent through HTTP/2 will bypass validation and be forwarded by mod_proxy, which can lead to request splitting or cache poisoning. This issue affects Apache HTTP Server 2.4.17 to 2.4.48.
- https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patch
- https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patch
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Revert "Add descriptions for CVE-2021-33193 CVE-2021-36160"
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Revert "Add descriptions for CVE-2021-33193 CVE-2021-36160"
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Add descriptions for CVE-2021-33193 CVE-2021-36160
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Add descriptions for CVE-2021-33193 CVE-2021-36160
- [debian-lts-announce] 20230303 [SECURITY] [DLA 3351-1] apache2 security update
- [debian-lts-announce] 20230303 [SECURITY] [DLA 3351-1] apache2 security update
- FEDORA-2021-5d2d4b6ac5
- FEDORA-2021-5d2d4b6ac5
- FEDORA-2021-f94985afca
- FEDORA-2021-f94985afca
- https://portswigger.net/research/http2
- https://portswigger.net/research/http2
- GLSA-202208-20
- GLSA-202208-20
- https://security.netapp.com/advisory/ntap-20210917-0004/
- https://security.netapp.com/advisory/ntap-20210917-0004/
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.tenable.com/security/tns-2021-17
- https://www.tenable.com/security/tns-2021-17
Modified: 2024-11-21
CVE-2021-34798
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.
- http://httpd.apache.org/security/vulnerabilities_24.html
- http://httpd.apache.org/security/vulnerabilities_24.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://kc.mcafee.com/corporate/index?page=content&id=SB10379
- https://kc.mcafee.com/corporate/index?page=content&id=SB10379
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update
- [debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update
- FEDORA-2021-dce7e7738e
- FEDORA-2021-dce7e7738e
- FEDORA-2021-e3f6dd670d
- FEDORA-2021-e3f6dd670d
- GLSA-202208-20
- GLSA-202208-20
- https://security.netapp.com/advisory/ntap-20211008-0004/
- https://security.netapp.com/advisory/ntap-20211008-0004/
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- DSA-4982
- DSA-4982
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.tenable.com/security/tns-2021-17
- https://www.tenable.com/security/tns-2021-17
Modified: 2024-11-21
CVE-2021-36160
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
- http://httpd.apache.org/security/vulnerabilities_24.html
- http://httpd.apache.org/security/vulnerabilities_24.html
- [httpd-bugs] 20211008 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211008 [Bug 65616] CVE-2021-36160 regression
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-bugs] 20211005 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211005 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211006 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211006 [Bug 65616] CVE-2021-36160 regression
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [httpd-bugs] 20211009 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211009 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211005 [Bug 65616] New: CVE-2021-36160 regression
- [httpd-bugs] 20211005 [Bug 65616] New: CVE-2021-36160 regression
- [httpd-bugs] 20211011 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211011 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211012 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211012 [Bug 65616] CVE-2021-36160 regression
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Revert "Add descriptions for CVE-2021-33193 CVE-2021-36160"
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Revert "Add descriptions for CVE-2021-33193 CVE-2021-36160"
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Add descriptions for CVE-2021-33193 CVE-2021-36160
- [httpd-cvs] 20210916 [httpd-site] branch main updated: Add descriptions for CVE-2021-33193 CVE-2021-36160
- [debian-lts-announce] 20210929 [SECURITY] [DLA 2768-1] uwsgi security update
- [debian-lts-announce] 20210929 [SECURITY] [DLA 2768-1] uwsgi security update
- [debian-lts-announce] 20211020 [SECURITY] [DLA 2768-2] uwsgi regression update
- [debian-lts-announce] 20211020 [SECURITY] [DLA 2768-2] uwsgi regression update
- FEDORA-2021-dce7e7738e
- FEDORA-2021-dce7e7738e
- FEDORA-2021-e3f6dd670d
- FEDORA-2021-e3f6dd670d
- GLSA-202208-20
- GLSA-202208-20
- https://security.netapp.com/advisory/ntap-20211008-0004/
- https://security.netapp.com/advisory/ntap-20211008-0004/
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- DSA-4982
- DSA-4982
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
Modified: 2024-11-21
CVE-2021-39275
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://httpd.apache.org/security/vulnerabilities_24.html
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update
- [debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update
- FEDORA-2021-dce7e7738e
- FEDORA-2021-dce7e7738e
- FEDORA-2021-e3f6dd670d
- FEDORA-2021-e3f6dd670d
- GLSA-202208-20
- GLSA-202208-20
- https://security.netapp.com/advisory/ntap-20211008-0004/
- https://security.netapp.com/advisory/ntap-20211008-0004/
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- DSA-4982
- DSA-4982
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
Modified: 2024-11-21
CVE-2021-40438
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-685781.pdf
- https://httpd.apache.org/security/vulnerabilities_24.html
- https://httpd.apache.org/security/vulnerabilities_24.html
- [httpd-users] 20211019 [users@httpd] Regarding CVE-2021-40438
- [httpd-users] 20211019 [users@httpd] Regarding CVE-2021-40438
- [httpd-bugs] 20211008 [Bug 65616] CVE-2021-36160 regression
- [httpd-bugs] 20211008 [Bug 65616] CVE-2021-36160 regression
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] Re: [External] : [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20210923 Re: [users@httpd] 2.4.49 security fixes: more info
- [httpd-users] 20211019 Re: [users@httpd] Regarding CVE-2021-40438
- [httpd-users] 20211019 Re: [users@httpd] Regarding CVE-2021-40438
- [debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update
- [debian-lts-announce] 20211002 [SECURITY] [DLA 2776-1] apache2 security update
- FEDORA-2021-dce7e7738e
- FEDORA-2021-dce7e7738e
- FEDORA-2021-e3f6dd670d
- FEDORA-2021-e3f6dd670d
- GLSA-202208-20
- GLSA-202208-20
- https://security.netapp.com/advisory/ntap-20211008-0004/
- https://security.netapp.com/advisory/ntap-20211008-0004/
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- 20211124 Multiple Vulnerabilities in Apache HTTP Server Affecting Cisco Products: November 2021
- DSA-4982
- DSA-4982
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpuapr2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.tenable.com/security/tns-2021-17
- https://www.tenable.com/security/tns-2021-17