製品・ソフトウェアに関する情報
Apache HTTP Server の ap_escape_quotes() におけるバッファの終わりを超えて書き込まれる脆弱性
Title Apache HTTP Server の ap_escape_quotes() におけるバッファの終わりを超えて書き込まれる脆弱性
Summary

Apache HTTP Server の ap_escape_quotes() には、バッファの終わりを超えて書き込まれる脆弱性が存在します。

Possible impacts 悪意のある入力を介して、バッファの終わりを超えて書き込まれ可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Sept. 16, 2021, midnight
Registration Date March 15, 2022, 11:59 a.m.
Last Update Sept. 22, 2025, 10:14 a.m.
CVSS3.0 : 緊急
Score 9.8
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS2.0 : 危険
Score 7.5
Vector AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected System
Apache Software Foundation
Apache HTTP Server 2.4.48 およびそれ以前
日立
Cosminexus HTTP Server 
Hitachi Web Server 
Hitachi Web Server - Custom Edition 
uCosminexus Application Server 
uCosminexus Application Server(64) 
uCosminexus Application Server-R 
uCosminexus Developer 
uCosminexus Primary Server Base 
uCosminexus Primary Server Base(64) 
uCosminexus Service Architect 
uCosminexus Service Platform 
uCosminexus Service Platform(64) 
Debian
Debian GNU/Linux 
Fedora Project
Fedora 
NetApp
ONTAP (旧 Clustered Data ONTAP) 
StorageGRID 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
No Changed Details Date of change
1 [2022年03月15日]
  掲載
March 15, 2022, 11:59 a.m.
2 [2025年09月19日]
  参考情報:JVN (JVNVU#99030761) を追加
  参考情報:ICS-CERT ADVISORY (ICSA-25-259-04) を追加
Sept. 19, 2025, 6:32 p.m.

NVD Vulnerability Information
CVE-2021-39275
Summary

ap_escape_quotes() may write beyond the end of a buffer when given malicious input. No included modules pass untrusted data to these functions, but third-party / external modules may. This issue affects Apache HTTP Server 2.4.48 and earlier.

Publication Date Sept. 17, 2021, 12:15 a.m.
Registration Date Sept. 17, 2021, 10 a.m.
Last Update Nov. 21, 2024, 3:19 p.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* 2.4.48
Configuration2 or higher or less more than less than
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:storagegrid:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:a:oracle:http_server:12.2.1.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:http_server:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:a:siemens:sinema_server:14.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:sinec_nms:*:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List