CVE-2021-30641Improper Input Validation in Apache Http Server

Severity
5.3MEDIUMNVD
EPSS
36.4%
top 2.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10
Latest updateMay 24

Description

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

Also affects: Debian Linux 10.0, 9.0, Fedora 34, 35

🔴Vulnerability Details

3
GHSA
GHSA-jfgv-4796-2jw7: Apache HTTP Server versions 22022-05-24
OSV
CVE-2021-30641: Apache HTTP Server versions 22021-06-10
CVEList
Unexpected URL matching with 'MergeSlashes OFF'2021-06-10

📋Vendor Advisories

5
Ubuntu
Apache HTTP Server vulnerabilities2021-06-21
Ubuntu
Apache HTTP Server vulnerabilities2021-06-21
Microsoft
Unexpected URL matching with 'MergeSlashes OFF'2021-06-08
Red Hat
httpd: Unexpected URL matching with 'MergeSlashes OFF'2021-06-04
Debian
CVE-2021-30641: apache2 - Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with '...2021
CVE-2021-30641 — Improper Input Validation in Apache | cvebase