CVE-2021-44790

CRITICALCVSS 9.8/10EPSS 97.11%

Last modified

CVE-2021-44790 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. EPSS estimates a 97.11% chance of exploitation in the next 30 days.

Description

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
97.11%

99.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
ApacheHttp Server< 2.4.52
FedoraprojectFedora34
FedoraprojectFedora35
FedoraprojectFedora36
DebianDebian Linux10.0
DebianDebian Linux11.0
TenableTenable.Sc>= 5.16.0, < 5.20.0
NetappCloud BackupAll versions
OracleCommunications Element Manager<= 9.0
OracleCommunications Operations Monitor4.3
OracleCommunications Operations Monitor4.4
OracleCommunications Operations Monitor5.0
OracleCommunications Session Report Manager<= 9.0
OracleCommunications Session Route Manager<= 9.0
OracleHttp Server12.2.1.3.0
OracleHttp Server12.2.1.4.0
OracleInstantis Enterprisetrack17.1
OracleInstantis Enterprisetrack17.2
OracleInstantis Enterprisetrack17.3
OracleZfs Storage Appliance Kit8.8
AppleMac Os X10.15.7Security Update 2020-001
AppleMacos< 10.15.7
AppleMacos>= 11.0, < 11.6.6
AppleMacos>= 12.0, < 12.4

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2021-44790?
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
How severe is CVE-2021-44790?
CVE-2021-44790 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 97.11% probability of exploitation in the next 30 days.
How do I fix CVE-2021-44790?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-44790?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST