CVE-2021-39275

Analyzed
Published: 16 Sept 2021, 14:40
Last modified:04 Aug 2024, 02:06

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
37.67% HIGH
38% probability -9.88%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Sept 2021, 14:40
Published
Vulnerability first disclosed
04 Aug 2024, 02:06
Last Modified
Vulnerability information updated

Description

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

CVSS Metrics

  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 37.67% Percentile: 97%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • apache software foundationapache http server

    ≥ Apache HTTP Server 2.4, ≤ 2.4.48

  • UnknownHTTP Server

    < 2.4.49

  • debiandebian_linux

    9.0 | 10.0 | 11.0

  • fedoraprojectfedora

    34 | 35

  • netappcloud_backup

    na

  • netappclustered_data_ontap

    na

  • netappstoragegrid

    na

  • oraclehttp_server

    12.2.1.3.0 | 12.2.1.4.0

  • oracleinstantis_enterprisetrack

    17.1 | 17.2 | 17.3

  • oraclezfs_storage_appliance_kit

    8.8

  • siemenssinema_server

    14.0

References (15)