First published: Sun Dec 05 2021(Updated: )
** DISPUTED ** M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
M-files M-files Web | <20.10.9524.1 | |
<20.10.9524.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-37253 is a vulnerability in M-Files Web before 20.10.9524.1 that allows a denial of service via overlapping ranges in HTTP requests with crafted Range or Request-Range headers.
CVE-2021-37253 has a high severity with a CVSS score of 7.5.
CVE-2021-37253 affects M-Files Web versions up to and excluding 20.10.9524.1.
The vulnerability can be exploited by sending HTTP requests with crafted Range or Request-Range headers containing overlapping ranges.
It is recommended to update M-Files Web to version 20.10.9524.1 or later to address the denial of service vulnerability.