CVE-2021-20325 Detail
This vulnerability is currently awaiting analysis.
Description
Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
Severity
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].
Weakness Enumeration
CWE-ID | CWE Name | Source |
---|---|---|
CWE-918 | Server-Side Request Forgery (SSRF) | Red Hat, Inc. |
CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | Red Hat, Inc. |
Change History
0 change records found show changes
Quick Info
CVE Dictionary Entry:
CVE-2021-20325
NVD Published Date:
02/18/2022
NVD Last Modified:
02/18/2022
Source:
Red Hat, Inc.