ZeroHour

CVE-2021-44790

PoC
CVSS 3.1
9.8 critical
EPSS
97%p100
Published
()
Modified
Description

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

Vendors
apachefedoraprojectdebiantenablenetapporacleapple
Products
http server, fedora, debian linux, tenable.sc, cloud backup, communications element manager, communications operations monitor, communications session report manager, communications session route manager, instantis enterprisetrack, zfs storage appliance kit, mac os x
Weakness
CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news