CVE-2021-30641

Updated: 2025-08-20 00:34:37.750061

Description:

Apache HTTP Server versions 2.4.39 to 2.4.46 Unexpected matching behavior with 'MergeSlashes OFF'


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

CentOS 8.4 ELS httpd 2.4.37 5.3 MEDIUM Released CLSA-2022:1643747448 2022-02-01 23:30:34
CentOS 8.5 ELS httpd 2.4.37 5.3 MEDIUM Not Vulnerable 2022-02-02 08:34:37
Ubuntu 16.04 ELS apache2 2.4.18 5.3 MEDIUM Released CLSA-2021:1635459129 2021-12-02 16:40:02