Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-22720

Опубликовано: 14 мар. 2022
Источник: redhat
CVSS3: 8.3
EPSS Средний

Описание

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

A flaw was found in httpd. The inbound connection is not closed when it fails to discard the request body, which may expose the server to HTTP request smuggling.

Меры по смягчению последствий

There are currently no known mitigations for this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9httpdNot affected
Red Hat JBoss Enterprise Application Platform 6httpdOut of support scope
JBoss Core Services for RHEL 8jbcs-httpd24-apr-utilFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-curlFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-httpdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_cluster-nativeFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_http2FixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_jkFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_mdFixedRHSA-2022:138920.04.2022
JBoss Core Services for RHEL 8jbcs-httpd24-mod_securityFixedRHSA-2022:138920.04.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2064321httpd: Errors encountered during the discarding of request body lead to HTTP request smuggling

EPSS

Процентиль: 97%
0.33369
Средний

8.3 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
nvd
почти 4 года назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

CVSS3: 9.8
msrc
почти 4 года назад

HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier

CVSS3: 9.8
debian
почти 4 года назад

Apache HTTP Server 2.4.52 and earlier fails to close inbound connectio ...

rocky
почти 4 года назад

Important: httpd:2.4 security update

EPSS

Процентиль: 97%
0.33369
Средний

8.3 High

CVSS3