47
CVE-2021-44790
PoC —CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
Modified
Description
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
- Vendors
- apachefedoraprojectdebiantenablenetapporacleapple
- Products
- http server, fedora, debian linux, tenable.sc, cloud backup, communications element manager, communications operations monitor, communications session report manager, communications session route manager, instantis enterprisetrack, zfs storage appliance kit, mac os x
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H