CVE-2021-33254

An issue was discovered in src/http/httpLib.c in EmbedThis Appweb Community Edition 8.2.1, allows attackers to cause a denial of service via the stream paramter to the parseUri function.
References
Link Resource
https://awxylitol.github.io/2021/05/09/embedthis-appweb-npd-bug.html Exploit Patch Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:embedthis:appweb:8.2.1:*:*:*:community:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

09 Jun 2022, 12:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CPE cpe:2.3:a:embedthis:appweb:8.2.1:*:*:*:community:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
CWE CWE-476
First Time Linux
Embedthis appweb
Linux linux Kernel
Embedthis
References (MISC) https://awxylitol.github.io/2021/05/09/embedthis-appweb-npd-bug.html - (MISC) https://awxylitol.github.io/2021/05/09/embedthis-appweb-npd-bug.html - Exploit, Patch, Third Party Advisory

02 Jun 2022, 14:53

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-02 14:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-33254

Mitre link : CVE-2021-33254

CVE.ORG link : CVE-2021-33254


JSON object : View

Products Affected

embedthis

  • appweb

linux

  • linux_kernel
CWE
CWE-476

NULL Pointer Dereference