Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-22720

Опубликовано: 14 мар. 2022
Источник: debian

Описание

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.53-1package
apache2fixed2.4.53-1~deb11u1bullseyepackage
apache2fixed2.4.38-3+deb10u8busterpackage

Примечания

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-22720

  • Fixed by: https://svn.apache.org/r1898692

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 8.3
redhat
около 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
nvd
около 4 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
msrc
около 4 лет назад

HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

rocky
около 4 лет назад

Important: httpd:2.4 security update