CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=2017321 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:o:redhat:enterprise_linux:8.5.0:*:*:*:*:*:*:*

History

30 Jun 2023, 17:06

Type Values Removed Values Added
CWE CWE-119 CWE-787

08 Mar 2022, 18:18

Type Values Removed Values Added
CWE CWE-119
CWE-918
CPE cpe:2.3:o:redhat:enterprise_linux:8.5.0:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
References (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2017321 - (MISC) https://bugzilla.redhat.com/show_bug.cgi?id=2017321 - Issue Tracking, Vendor Advisory
First Time Redhat enterprise Linux
Redhat

18 Feb 2022, 18:33

Type Values Removed Values Added
New CVE

Information

Published : 2022-02-18 18:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-20325

Mitre link : CVE-2021-20325

CVE.ORG link : CVE-2021-20325


JSON object : View

Products Affected

redhat

  • enterprise_linux
CWE
CWE-787

Out-of-bounds Write

CWE-918

Server-Side Request Forgery (SSRF)

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer