vulnerability
Apache HTTPD: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier (CVE-2022-22720)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | 2022-03-14 | 2022-04-25 | 2024-12-09 |
Severity
7
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
2022-03-14
Added
2022-04-25
Modified
2024-12-09
Description
Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling
Solution
apache-httpd-upgrade-latest
References
- URL-http://seclists.org/fulldisclosure/2022/May/33
- URL-http://seclists.org/fulldisclosure/2022/May/35
- URL-http://seclists.org/fulldisclosure/2022/May/38
- URL-http://www.openwall.com/lists/oss-security/2022/03/14/3
- URL-https://httpd.apache.org/security/vulnerabilities_24.html
- URL-https://lists.debian.org/debian-lts-announce/2022/03/msg00033.html
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/
- URL-https://security.gentoo.org/glsa/202208-20
- URL-https://security.netapp.com/advisory/ntap-20220321-0001/
- URL-https://support.apple.com/kb/HT213255
- URL-https://support.apple.com/kb/HT213256
- URL-https://support.apple.com/kb/HT213257
- URL-https://www.oracle.com/security-alerts/cpuapr2022.html
- URL-https://www.oracle.com/security-alerts/cpujul2022.html
- CVE-2022-22720
- https://attackerkb.com/topics/CVE-2022-22720

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.