peter bassill · operator
$ cve CVE-2021-44790 JSON

CVE-2021-44790 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 96.8% (pctl 100)

Patch early

A public exploit exists.

Description

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS96.84% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVno
Public exploityes
Published2021-12-20
Last modified2026-06-17

Affected (14)

VendorProduct
apachehttp server
applemac os x
applemacos
debiandebian linux
fedoraprojectfedora
netappcloud backup
oraclecommunications element manager
oraclecommunications operations monitor
oraclecommunications session report manager
oraclecommunications session route manager
oraclehttp server
oracleinstantis enterprisetrack
oraclezfs storage appliance kit
tenabletenable.sc

Public exploits

SourceTitleDate
exploit-dbApache 2.4.x - Buffer Overflow2023-04-01

References

→ the Explorer  ·  watch your stack  ·  NVD