Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22720

Опубликовано: 14 мар. 2022
Источник: redhat
CVSS3: 8.3

Описание

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

A flaw was found in httpd. The inbound connection is not closed when it fails to discard the request body, which may expose the server to HTTP request smuggling.

Меры по смягчению последствий

There are currently no known mitigations for this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpdOut of support scope
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_cluster-nativeFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2022:138920.04.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2064321httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
больше 3 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
nvd
больше 3 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
msrc
больше 3 лет назад

HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

CVSS3: 9.8
debian
больше 3 лет назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connectio ...

rocky
больше 3 лет назад

Important: httpd:2.4 security update

8.3 High

CVSS3