CVE-2021-36160
—CVSS 3.1
7.5 high
EPSS
63%p99
Published
()
Modified
Description
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
- Vendors
- apachefedoraprojectdebiannetapporaclebroadcom
- Products
- http server, fedora, debian linux, cloud backup, clustered data ontap, storagegrid, communications cloud native core network function cloud native environment, enterprise manager base platform, instantis enterprisetrack, peoplesoft enterprise peopletools, zfs storage appliance kit, brocade fabric operating system firmware
- Weakness
- CWE-125
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.