CVE-2021-39275: stato di sfruttamento e disponibilità della patch
CVE-2021-39275 · CVSS 9.8 CRITICAL · EPSS 39%
ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2021-39275 viene sfruttato?
Non è nel catalogo CISA KEV.
EPSS stima la probabilità di sfruttamento nei prossimi 30 giorni al 39%.
Codice di exploit pubblico: nessuno trovato nelle fonti monitorate.
Quali prodotti e versioni sono interessati?
Nessun elenco di pacchetti interessati registrato qui.