Description:
The Apache Software Foundation released a security update to address multiple vulnerabilities in the HTTP Server and its modules. A remote attacker could exploit the vulnerabilities by sending a specially crafted request to the affected systems.
Affected Systems:
- Apache versions 2.4.0 to 2.4.46
Impact:
Depending on the vulnerability exploited, a successful exploitation could lead to denial of service, information disclosure or security restriction bypass on an affected system.
Recommendation:
The Apache Software Foundation has released new version of the product to address the issues and they can be downloaded at the following URL:
https://httpd.apache.org/download.cgi#apache24
More Information:
- https://httpd.apache.org/download.cgi#apache24
- https://www.hkcert.org/security-bulletin/apache-http-server-multiple-vulnerabilities_20210615
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17567
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13938
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-13950
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-35452
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26690
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-26691
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-30641
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-31618