Fiche vulnérabilité
CVE-2021-36160 : faille élevée apache http server (CVSS 7.5)
Description
A carefully crafted request uri-path can cause mod_proxy_uwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 16 sept. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- apache http server
- fedoraproject fedora
- debian debian linux
- netapp cloud backup
- netapp clustered data ontap
- netapp storagegrid
- oracle communications cloud native core network function cloud native environment
- oracle enterprise manager base platform
- oracle http server
- oracle instantis enterprisetrack
- oracle peoplesoft enterprise peopletools
- oracle zfs storage appliance kit
- broadcom brocade fabric operating system firmware
Références
- Fiche CVE-2021-36160 sur le NVD (NIST)
- httpd.apache.org/security/vulnerabilities_24.html
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.apache.org/thread…
- lists.debian.org/debian-lts-announce/2021/09/msg00016.html