CVE-2021-20325
Last modified
CVE-2021-20325 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. EPSS estimates a 1.57% chance of exploitation in the next 30 days.
Description
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Enterprise Linux | 8.5.0 |
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2017321Issue Tracking, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2017321Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-20325?
How severe is CVE-2021-20325?
How do I fix CVE-2021-20325?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-2032Vulnerability in the MySQL Server product of Oracle MySQL (c…4.3
- CVE-2021-20320A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s3…5.5
- CVE-2021-20321A race condition accessing file object in the Linux kernel O…4.7
- CVE-2021-20322A flaw in the processing of received ICMP errors (ICMP fragm…7.4
- CVE-2021-20323A POST based reflected Cross Site Scripting vulnerability on…6.1
- CVE-2021-20324Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-20326A user authorized to performing a specific type of find quer…6.5
- CVE-2021-20327A specific version of the Node.js mongodb-client-encryption …6.8
- CVE-2021-20328Specific versions of the Java driver that support client-sid…6.8
- CVE-2021-20329Specific cstrings input may not be properly validated in the…6.5
- CVE-2021-2033Vulnerability in the Oracle WebLogic Server product of Oracl…4.3
- CVE-2021-20330An attacker with basic CRUD permissions on a replicated coll…6.5
Are you affected by CVE-2021-20325?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
