cbcvebase.
CVE-2021-30641
published 2021-06-10

CVE-2021-30641: Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

PriorityP343medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
52.33%
98.8th percentile
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'

Affected

17 ranges
VendorProductVersion rangeFixed in
apachehttp_server2.4.39 – 2.4.46
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
debianapache2< apache2 2.4.46-6 (bookworm)apache2 2.4.46-6 (bookworm)
debiandebian_linux
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.46-10_on_cbl_mariner_2.0
msrccm1_httpd_2.4.46-5_on_cbl_mariner_1.0
oracleenterprise_manager_ops_center
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oracleinstantis_enterprisetrack
oraclezfs_storage_appliance_kit

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability affects Apache HTTP Server versions 2.4.39 through 2.4.46 when the MergeSlashes directive is involved; monitor for unexpected URL matching behavior on servers running these versions with MergeSlashes configured.
  • The flaw was introduced as a regression from the fix for CVE-2019-0220; systems patched for that CVE in the affected version range are likely vulnerable and should be prioritized for detection/patching.
  • The upstream Apache bug report and patch commit can be used to diff behavior and build regression tests: review commit eb986059aa5aa0b6c1d52714ea83e3dd758afdd1 in the Apache httpd repository for the exact code change.
  • ·Setting 'MergeSlashes OFF' is cited as a mitigation, but the vulnerability is specifically about unexpected behavior when this directive is used — verify that toggling this directive does not introduce other routing/security issues in the specific deployment.
  • ·The highest threat from this vulnerability is to data integrity (not confidentiality or availability), meaning access controls or routing rules relying on URL normalization may be silently bypassed.

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.