CVE-2021-44790

CVE-2021-44790: Possible buffer overflow when parsing multipart content in mod_lua of Apache HTTP Server 2.4.51 and earlier

Vendor Apache Software Foundation
Product Apache HTTP Server
Weakness CWE-787
Published December 20, 2021
Last update August 4, 2024

CVSS base score

What the vulnerability does

Description

A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.

Key dates

Disclosure timeline

December 20, 2021 CVE published
August 4, 2024 Record updated