Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-30641

Опубликовано: 04 июн. 2021
Источник: redhat
CVSS3: 5.9
EPSS Средний

Описание

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

A flaw was found in Apache httpd. A possible regression from an earlier security fix broke behavior of MergeSlashes. The highest threat from this vulnerability is to data integrity.

Отчет

This flaw was introduced when fixing https://access.redhat.com/security/cve/cve-2019-0220, therefore versions of httpd package shipped with Red Hat Enterprise Linux 7, 8 and Red Hat Software Collections are affected by this flaw.

Меры по смягчению последствий

This issue can be mitigated by setting the "MergeSlashes" directive to OFF

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6httpdNot affected
Red Hat Enterprise Linux 7httpdOut of support scope
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpd22Out of support scope
Red Hat JBoss Enterprise Web Server 2httpd22Out of support scope
Red Hat Software Collectionshttpd24-httpdWill not fix
JBoss Core Services for RHEL 8jbcs-httpd24-aprFixedRHSA-2021:461410.11.2021
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2021:461410.11.2021
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2021:461410.11.2021
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2021:461410.11.2021

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1966743httpd: Unexpected URL matching with 'MergeSlashes OFF'

EPSS

Процентиль: 95%
0.18342
Средний

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 4 лет назад

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

CVSS3: 5.3
nvd
около 4 лет назад

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

CVSS3: 5.3
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 5.3
debian
около 4 лет назад

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behav ...

github
около 3 лет назад

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

EPSS

Процентиль: 95%
0.18342
Средний

5.9 Medium

CVSS3