Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities
November 3, 2021Rewterz Threat Alert – Kimsuky – Active IOCs
November 4, 2021Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities
November 3, 2021Rewterz Threat Alert – Kimsuky – Active IOCs
November 4, 2021Severity
Medium
Analysis Summary
CVE-2021-27644
Apache could allow a remote authenticated attacker to execute arbitrary code on the system, caused by unsafe deserialization in the mysql jdbc connector parameters. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2021-41973
Apache MINA is vulnerable to a denial of service, caused by a flaw in the HTTP Header decoder. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to cause the HTTP Header decoder to loop indefinitely, and result in a denial of service condition.
Impact
- Code Execution
- Denial of Service
Affected Vendors
Apache
Affected Products
- Apache DolphinScheduler 1.3.5
- Apache MINA 2.0
- Apache MINA 2.1
Remediation
Upgrade to the latest version of Apache, available from the Apache Web site
CVE-2021-27644
CVE-2021-41973