Rewterz
Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
September 13, 2021
Rewterz
Rewterz Threat Advisory – Multiple Apache Any23 Vulnerabilities
September 14, 2021

Rewterz Threat Advisory – CVE-2021-33193 – Apache Mod_Proxy HTTP/2 Vulnerability

Severity

Medium

Analysis Summary

CVE-2021-33193

Apache HTTP Server is vulnerable to HTTP request splitting attacks, caused by improper input validation in HTTP/2 message processing. A remote attacker could exploit this vulnerability to inject arbitrary HTTP requests and cause the browser to send 2 HTTP requests, once the URL is clicked. This would allow the attacker to perform further attacks, such as Web cache poisoning or cross-site scripting.

Impact

  • Cross-site scripting.
  • Unauthorized Access

Affected Vendors

Apache

Affected Products

  • Apache HTTP Server 2.4.17 to 2.4.48.

Remediation

Upgrade to the latest version of Apache HTTP Server (2.4.49 or later), available from the Apache GIT Repository.

https://github.com/apache/httpd/commit/ecebcc035ccd8d0e2984fe41420d9e944f456b3c.patch