CVE-2021-40438 | Techzone
Summary
Airlock Gateway uses Apache HTTP server as a web listener for the WAF/API Gateway engine as well as for the Configuration Center. mod_status is not used by default by Airlock Gateway but is available and can be enabled with Apache Expert Settings [3]. Our custom Apache module mod_airlock does not use the affected function ap_escape_quotes. Affects mod_proxy which is used by the Configuration Center Management Apache Server. Airlock Gateway is not affected because the static configuration of mod_proxy is safe, i.e. the vulnerability can not be exploited.
Classifications
industries
Telecommunications
applications
Business Planning / Continuity
AskAI Classifications
Labels
Software Development
SaaS
Standard Software
Linked Companies
Ergon Informatik AG
$10M to $25M