Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
September 13, 2021Rewterz Threat Advisory – Multiple Apache Any23 Vulnerabilities
September 14, 2021Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
September 13, 2021Rewterz Threat Advisory – Multiple Apache Any23 Vulnerabilities
September 14, 2021Severity
Medium
Analysis Summary
CVE-2021-33193
Apache HTTP Server is vulnerable to HTTP request splitting attacks, caused by improper input validation in HTTP/2 message processing. A remote attacker could exploit this vulnerability to inject arbitrary HTTP requests and cause the browser to send 2 HTTP requests, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting.
Impact
- Cross-site scripting.
- Unauthorized Access
Affected Vendors
Apache
Affected Products
- Apache HTTP Server 2.4.17 to 2.4.48.
Remediation
Upgrade to the latest version of Apache HTTP Server (2.4.49 or later), available from the Apache GIT Repository.
https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patch