Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade mod_sessionUpgrade mod_http2Upgrade mod_sslUpgrade mod_proxy_htmlUpgrade httpd-filesystemUpgrade mod_ldapUpgrade httpdUpgrade httpd-develUpgrade mod_mdUpgrade httpd-toolsUpgrade httpd-manual | May 4, 2022 | Feb 18, 2022 |
| Centos_linux | — | Upgrade httpd-tools-debuginfoUpgrade httpd-debuginfoUpgrade httpd-filesystemUpgrade httpd-develUpgrade mod_ssl-debuginfoUpgrade mod_session-debuginfoUpgrade mod_proxy_html-debuginfoUpgrade mod_md-debugsourceUpgrade mod_ldapUpgrade httpdUpgrade mod_sslUpgrade httpd-toolsUpgrade mod_md-debuginfoUpgrade mod_http2-debuginfoUpgrade httpd-manualUpgrade mod_http2-debugsourceUpgrade mod_mdUpgrade mod_ldap-debuginfoUpgrade mod_proxy_htmlUpgrade mod_http2Upgrade mod_sessionUpgrade httpd-debugsource | Nov 11, 2021 | Nov 9, 2021 |
| Oracle_linux | — | Upgrade mod_proxy_htmlUpgrade httpd-filesystemUpgrade mod_sessionUpgrade mod_http2Upgrade mod_mdUpgrade mod_ldapUpgrade mod_sslUpgrade httpd-toolsUpgrade httpd-manualUpgrade httpd-develUpgrade httpd | Nov 19, 2021 | Nov 9, 2021 |
| Redhat_linux | — | Upgrade mod_session-debuginfoUpgrade mod_http2-debuginfoUpgrade httpd-develUpgrade mod_mdUpgrade mod_ldap-debuginfoUpgrade mod_ssl-debuginfoUpgrade mod_http2Upgrade mod_md-debugsourceUpgrade mod_proxy_htmlUpgrade httpd-filesystemUpgrade mod_md-debuginfoUpgrade mod_ldapUpgrade httpd-manualUpgrade httpd-debuginfoUpgrade mod_proxy_html-debuginfoUpgrade httpd-tools-debuginfoUpgrade httpd-debugsourceUpgrade httpd-toolsUpgrade mod_http2-debugsourceUpgrade mod_sessionUpgrade httpdUpgrade mod_ssl | Nov 11, 2021 | Nov 9, 2021 |
| Rocky_linux | — | Upgrade httpd-debuginfoUpgrade mod_sessionUpgrade httpd-tools-debuginfoUpgrade mod_ldapUpgrade mod_ssl-debuginfoUpgrade httpdUpgrade httpd-debugsourceUpgrade mod_md-debugsourceUpgrade mod_http2-debuginfoUpgrade mod_mdUpgrade mod_http2-debugsourceUpgrade mod_proxy_htmlUpgrade mod_session-debuginfoUpgrade mod_md-debuginfoUpgrade mod_proxy_html-debuginfoUpgrade mod_sslUpgrade mod_ldap-debuginfoUpgrade mod_http2Upgrade httpd-toolsUpgrade httpd-devel | Mar 12, 2024 | Feb 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub