ZeroHour

CVE-2021-36160

CVSS 3.1
7.5 high
EPSS
63%p99
Published
()
Modified
Description

A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).

Vendors
apachefedoraprojectdebiannetapporaclebroadcom
Products
http server, fedora, debian linux, cloud backup, clustered data ontap, storagegrid, communications cloud native core network function cloud native environment, enterprise manager base platform, instantis enterprisetrack, peoplesoft enterprise peopletools, zfs storage appliance kit, brocade fabric operating system firmware
Weakness
CWE-125
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.