Missing fixes for CVE-2021-40438 and CVE-2021-26691 in the versions of httpd, as shipped in Red Hat Enterprise Linux 8.5.0, causes a security regression compared to the versions shipped in Red Hat Enterprise Linux 8.4. A user who installs or updates to Red Hat Enterprise Linux 8.5.0 would be vulnerable to the mentioned CVEs, even if they were properly fixed in Red Hat Enterprise Linux 8.4. CVE-2021-20325 was assigned to that Red Hat specific security regression and it does not affect the upstream versions of httpd.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade httpd-toolsUpgrade httpd-develUpgrade httpd-manualUpgrade mod_mdUpgrade httpdUpgrade mod_ldapUpgrade httpd-filesystemUpgrade mod_sessionUpgrade mod_proxy_htmlUpgrade mod_http2Upgrade mod_ssl | May 4, 2022 | Feb 18, 2022 |
| Centos_linux | — | Upgrade mod_session-debuginfoUpgrade httpdUpgrade httpd-filesystemUpgrade mod_ldapUpgrade mod_proxy_html-debuginfoUpgrade mod_ssl-debuginfoUpgrade httpd-debuginfoUpgrade httpd-tools-debuginfoUpgrade mod_md-debugsourceUpgrade httpd-develUpgrade mod_proxy_htmlUpgrade mod_mdUpgrade mod_ldap-debuginfoUpgrade mod_http2-debugsourceUpgrade httpd-toolsUpgrade mod_sslUpgrade mod_http2-debuginfoUpgrade httpd-manualUpgrade httpd-debugsourceUpgrade mod_sessionUpgrade mod_md-debuginfoUpgrade mod_http2 | Nov 11, 2021 | Nov 9, 2021 |
| Oracle_linux | — | Upgrade httpd-develUpgrade httpd-manualUpgrade mod_sslUpgrade httpd-toolsUpgrade httpdUpgrade mod_proxy_htmlUpgrade mod_sessionUpgrade mod_ldapUpgrade httpd-filesystemUpgrade mod_http2Upgrade mod_md | Nov 19, 2021 | Nov 9, 2021 |
| Redhat_linux | — | Upgrade httpdUpgrade httpd-debugsourceUpgrade httpd-tools-debuginfoUpgrade mod_sslUpgrade httpd-debuginfoUpgrade mod_sessionUpgrade mod_http2-debugsourceUpgrade mod_proxy_html-debuginfoUpgrade mod_ldapUpgrade httpd-toolsUpgrade mod_md-debuginfoUpgrade httpd-manualUpgrade mod_mdUpgrade mod_ssl-debuginfoUpgrade mod_ldap-debuginfoUpgrade mod_md-debugsourceUpgrade httpd-filesystemUpgrade mod_session-debuginfoUpgrade mod_proxy_htmlUpgrade mod_http2Upgrade httpd-develUpgrade mod_http2-debuginfo | Nov 11, 2021 | Nov 9, 2021 |
| Rocky_linux | — | Upgrade mod_ssl-debuginfoUpgrade httpd-debugsourceUpgrade httpdUpgrade httpd-tools-debuginfoUpgrade httpd-debuginfoUpgrade mod_sessionUpgrade mod_ldapUpgrade mod_sslUpgrade mod_http2-debuginfoUpgrade httpd-toolsUpgrade mod_md-debugsourceUpgrade httpd-develUpgrade mod_http2-debugsourceUpgrade mod_proxy_html-debuginfoUpgrade mod_session-debuginfoUpgrade mod_mdUpgrade mod_md-debuginfoUpgrade mod_ldap-debuginfoUpgrade mod_proxy_htmlUpgrade mod_http2 | Mar 12, 2024 | Feb 18, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub