CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=2017321 Issue Tracking Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2017321 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:redhat:enterprise_linux:8.5.0:*:*:*:*:*:*:*

History

21 Nov 2024, 05:46

Type Values Removed Values Added
References () https://bugzilla.redhat.com/show_bug.cgi?id=2017321 - Issue Tracking, Vendor Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=2017321 - Issue Tracking, Vendor Advisory

30 Jun 2023, 17:06

Type Values Removed Values Added
CWE CWE-119 CWE-787

Information

Published : 2022-02-18 18:15

Updated : 2024-11-21 05:46


NVD link : CVE-2021-20325

Mitre link : CVE-2021-20325

CVE.ORG link : CVE-2021-20325


JSON object : View

Products Affected

redhat

  • enterprise_linux
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-787

Out-of-bounds Write

CWE-918

Server-Side Request Forgery (SSRF)