ZeroHour

CVE-2021-39275

CVSS 3.1
9.8 critical
EPSS
39%p99
Published
()
Modified
Description

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

Vendors
apachefedoraprojectdebiannetapporaclesiemens
Products
http server, fedora, debian linux, cloud backup, clustered data ontap, storagegrid, instantis enterprisetrack, zfs storage appliance kit, sinec nms, sinema server
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news