← All CVEs

CVE-2021-44790

critical · 9.8

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

9.8
CVSS
96.8%
EPSS (exploit prob.)
100th
EPSS percentile
2021-12-20
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-787

Affected products

VendorProductAffected versions
apachehttp_server< 2.4.52
fedoraprojectfedora34
fedoraprojectfedora35
fedoraprojectfedora36
debiandebian_linux10.0
debiandebian_linux11.0
tenabletenable.sc>= 5.16.0, < 5.20.0
netappcloud_backupall versions
oraclecommunications_element_manager<= 9.0
oraclecommunications_operations_monitor4.3
oraclecommunications_operations_monitor4.4
oraclecommunications_operations_monitor5.0
oraclecommunications_session_report_manager<= 9.0
oraclecommunications_session_route_manager<= 9.0
oraclehttp_server12.2.1.3.0
oraclehttp_server12.2.1.4.0
oracleinstantis_enterprisetrack17.1
oracleinstantis_enterprisetrack17.2
oracleinstantis_enterprisetrack17.3
oraclezfs_storage_appliance_kit8.8
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemac_os_x10.15.7
applemacos< 10.15.7
applemacos>= 11.0, < 11.6.6
applemacos>= 12.0, < 12.4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-44790