Rewterz
Rewterz Threat Advisory – Multiple NVIDIA vGPU Software Vulnerabilities
November 2, 2021
Rewterz
Rewterz Threat Alert – FormBook Malware – Active IOCs
November 2, 2021

Rewterz Threat Advisory – Multiple Apache Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-27644 

Apache could allow a remote authenticated attacker to execute arbitrary code on the system, caused by an unsafe deserialization in the mysql jdbc connector parameters. By sending specially-crafted input, an attacker could exploit this vulnerability to execute arbitrary code on the system.

CVE-2021-41973 

Apache MINA is vulnerable to a denial of service, caused by a flaw in the HTTP Header decoder. By sending a specially-crafted HTTP request, a remote attacker could exploit this vulnerability to cause the HTTP Header decoder to loop indefinitely, and results in a denial of service condition.

Impact

  • Code Execution
  • Denial of Service

Affected Vendors

Apache

Affected Products

  • Apache Storm 1.0.0
  • Apache Storm 2.1.0
  • Apache Storm 2.2.0

Remediation

Upgrade to the latest version of Apache Storm, available from the Apache Web site.https://storm.apache.org/