CVE-2021-20325

Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
References
Link Resource
https://bugzilla.redhat.com/show_bug.cgi?id=2017321 Issue Tracking Vendor Advisory
Configurations

Configuration 1

cpe:2.3:o:redhat:enterprise_linux:8.5.0:*:*:*:*:*:*:*

Information

Published : 2022-02-18 06:15

Updated : 2022-03-08 06:18


NVD link : CVE-2021-20325

Mitre link : CVE-2021-20325

Products Affected
No products.
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-918

Server-Side Request Forgery (SSRF)