Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22720

Опубликовано: 14 мар. 2022
Источник: redhat
CVSS3: 8.3
EPSS Средний

Описание

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

A flaw was found in httpd. The inbound connection is not closed when it fails to discard the request body, which may expose the server to HTTP request smuggling.

Меры по смягчению последствий

There are currently no known mitigations for this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpdOut of support scope
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_cluster-nativeFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2022:138920.04.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2064321httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling

EPSS

Процентиль: 97%
0.32823
Средний

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
nvd
больше 3 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 9.8
debian
больше 3 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connectio ...

rocky
около 3 лет назад

Important: httpd:2.4 security update

EPSS

Процентиль: 97%
0.32823
Средний

8.3 High

CVSS3