Rewterz
Rewterz Threat Advisory – Multiple Mozilla Firefox Vulnerabilities
November 3, 2021
Rewterz
Rewterz Threat Alert – Kimsuky – Active IOCs
November 4, 2021

Rewterz Threat Advisory – Multiple Apache Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2021-27644 

Apache could allow a remote authenticated attacker to execute arbitrary code on the system, caused by unsafe deserialization in the mysql jdbc connector parameters. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2021-41973 

Apache MINA is vulnerable to a denial of service, caused by a flaw in the HTTP Header decoder. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to cause the HTTP Header decoder to loop indefinitely, and result in a denial of service condition.

Impact

  • Code Execution
  • Denial of Service

Affected Vendors

Apache

Affected Products

  • Apache DolphinScheduler 1.3.5
  • Apache MINA 2.0
  • Apache MINA 2.1

Remediation

Upgrade to the latest version of Apache, available from the Apache Web site

CVE-2021-27644

https://dolphinscheduler.apache.org/

CVE-2021-41973

https://seclists.org/oss-sec/2021/q4/76