CVE-2021-33620medium

CVE-2021-33620

Published · Updated

35Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 80%
exploitation probability
80%top 1% of all CVEs
observed exploitation
nono source reports it
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Affected
2 products (8 components)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Fixed
1 product (30 components)
Red Hat Enterprise Linux AppStream (v. 8)
Not affected
1 product (2 components) — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 9
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:L/S:U/UI:N
Affected products
n/a · n/a