Rewterz Threat Advisory – Multiple NVIDIA vGPU Software Vulnerabilities
November 2, 2021Rewterz Threat Alert – FormBook Malware – Active IOCs
November 2, 2021Rewterz Threat Advisory – Multiple NVIDIA vGPU Software Vulnerabilities
November 2, 2021Rewterz Threat Alert – FormBook Malware – Active IOCs
November 2, 2021Severity
High
Analysis Summary
CVE-2021-27644
Apache could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the mysql jdbc connector parameters. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.
CVE-2021-41973
Apache MINA is vulnerable to a denial of service, caused by a flaw in the HTTP Header decoder. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to cause the HTTP Header decoder to loop indefinitely, and results in a denial of service condition.
Impact
- Code Execution
- Denial of Service
Affected Vendors
Apache
Affected Products
- Apache Storm 1.0.0
- Apache Storm 2.1.0
- Apache Storm 2.2.0
Remediation
Upgrade to the latest version of Apache Storm, available from the Apache Web site.https://storm.apache.org/