Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-31813

Опубликовано: 09 июн. 2022
Источник: debian
EPSS Низкий

Описание

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
apache2fixed2.4.54-1package
apache2fixed2.4.54-1~deb11u1bullseyepackage
apache2fixed2.4.38-3+deb10u8busterpackage

Примечания

  • https://www.openwall.com/lists/oss-security/2022/06/08/8

  • https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-31813

  • https://github.com/apache/httpd/commit/956f708b094698ac9ad570d640d4f30eb0df7305

  • https://www.synacktiv.com/publications/cve-2022-31813-forwarding-addresses-is-hard.html

EPSS

Процентиль: 11%
0.00039
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

CVSS3: 7.3
redhat
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

CVSS3: 9.8
nvd
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

CVSS3: 9.8
github
около 3 лет назад

Apache HTTP Server 2.4.53 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

oracle-oval
почти 3 года назад

ELSA-2022-9682: httpd:2.4 security update (IMPORTANT)

EPSS

Процентиль: 11%
0.00039
Низкий