CVE-2021-30641: Unexpected URL matching with 'MergeSlashes OFF'
A flaw was found in Apache httpd. A possible regression from an earlier security fix broke behavior of MergeSlashes. The highest threat from this vulnerability is to data integrity.
Other sources
Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'
Possible regression from security fix broke behavior of MergeSlashes.
References:
https://bz.apache.org/bugzilla/showbug.cgi?id=65238 https://github.com/apache/httpd/commit/eb986059aa5aa0b6c1d52714ea83e3dd758afdd1
— Red Hat
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2021-30641?
CVE-2021-30641 is a vulnerability found in Apache HTTP Server versions 2.4.39 to 2.4.46 that causes unexpected matching behavior with MergeSlashes OFF.
What is the severity of CVE-2021-30641?
The severity of CVE-2021-30641 is medium with a severity value of 5.9.
How does CVE-2021-30641 affect data integrity?
CVE-2021-30641 poses a threat to data integrity.
Which software versions are affected by CVE-2021-30641?
Apache HTTP Server versions 2.4.39 to 2.4.46 are affected by CVE-2021-30641.
How can I fix CVE-2021-30641?
To fix CVE-2021-30641, update Apache HTTP Server to version 2.4.47.