Lucene search

K
f5F5F5:K20622400
HistoryOct 25, 2021 - 12:00 a.m.

K20622400 : Apache HTTP server vulnerability CVE-2021-39275

2021-10-2500:00:00
my.f5.com
54

9.9 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.5%

Security Advisory Description

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier. (CVE-2021-39275)

Impact

This vulnerability allows an unauthenticated remote attacker to cause a denial-of-service (DoS) on the server or potentially execute code on the system with the privileges of the httpduser, by providing malicious input to the function.