CVE-2021-40438 | Techzone

General News

Summary

Airlock Gateway uses Apache HTTP server as a web listener for the WAF/API Gateway engine as well as for the Configuration Center. mod_status is not used by default by Airlock Gateway but is available and can be enabled with Apache Expert Settings [3]. Our custom Apache module mod_airlock does not use the affected function ap_escape_quotes. Affects mod_proxy which is used by the Configuration Center Management Apache Server. Airlock Gateway is not affected because the static configuration of mod_proxy is safe, i.e. the vulnerability can not be exploited.

Classifications

industries
Telecommunications
applications
Business Planning / Continuity

AskAI Classifications

Labels
Software Development SaaS Standard Software

Linked Companies

Ergon Informatik AG
$10M to $25M