CVE-2021-33620medium

CVE-2021-33620

Publicada el · Actualizada el

35Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 6.5epss 80%
probabilidad de explotación
80%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
Lo que declaran los fabricantes (VEX)

Declaraciones oficiales de los fabricantes en formato CSAF/VEX: si su producto está afectado, ya corregido o descartado — y por qué. Es afirmación del fabricante, no juicio de Vexday.

Afectado
2 productos (8 componentes)
Red Hat Enterprise Linux 6 · Red Hat Enterprise Linux 7
workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Corregido
1 producto (30 componentes)
Red Hat Enterprise Linux AppStream (v. 8)
No afectado
1 producto (2 componentes) — porque el código vulnerable no está presente en el producto
Red Hat Enterprise Linux 9
Squid before 4.15 and 5.x before 5.0.6 allows remote servers to cause a denial of service (affecting availability to all clients) via an HTTP response. The issue trigger is a header that can be expected to exist in HTTP traffic without any malicious intent by the server.
CVSS:3.1/AC:L/AV:N/A:H/C:N/I:N/PR:L/S:U/UI:N
Productos afectados
n/a · n/a