PT-2022-3356 · Apache+10 · Apache Http Server+10

Ricter Z

·

Published

2022-03-02

·

Updated

2025-09-29

·

CVE-2022-26377

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.53 and prior versions
Description The issue is related to the inconsistent interpretation of HTTP requests, also known as 'HTTP Request Smuggling', in the mod proxy ajp module of the Apache HTTP Server. This allows an attacker to smuggle requests to the AJP server it forwards requests to. The exploitation of this issue can enable a remote attacker to send a specially crafted HTTP request to the server and redirect requests to the AJP server. There is no information about the estimated number of potentially affected devices worldwide or real-world incidents where this issue was exploited.
Recommendations For Apache HTTP Server versions 2.4.53 and prior versions, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Out of bounds Read

Integer Overflow

Allocation of Resources Without Limits

HTTP Request/Response Smuggling

Insufficient Verification of Data Authenticity

Information Disclosure

Improper Authentication

Related Identifiers

ALSA-2022:7647
ALSA-2022:8067
ALSA-2022_7647
ALSA-2022_8067
ALSA-2025_16880
ALT-PU-2022-2087
ALT-PU-2022-2093
ALT-PU-2022-2095
ALT-PU-2023-1260
BDU:2022-04101
BDU:2022-04102
BDU:2022-04106
BDU:2022-04115
BDU:2022-04141
BDU:2022-04145
BDU:2022-04146
BDU:2022-04147
BIT-APACHE-2022-26377
CESA-2022_7647
CVE-2022-26377
ELSA-2022-7647
ELSA-2022-8067
MGASA-2022-0228
OESA-2022-1718
OPENSUSE-SU-2022_2302-1
OPENSUSE-SU-2022_2342-1
OPENSUSE-SU-2024:12142-1
RHSA-2022:6753
RHSA-2022:7647
RHSA-2022:8067
RHSA-2022:8840
RHSA-2022_7647
RHSA-2022_8067
RLSA-2022:7647
RLSA-2022:8067
RLSA-2022_7647
RLSA-2022_8067
SUSE-SU-2022:2099-1
SUSE-SU-2022:2101-1
SUSE-SU-2022:2302-1
SUSE-SU-2022:2338-1
SUSE-SU-2022:2342-1
SUSE-SU-2022_2099-1
SUSE-SU-2022_2101-1
SUSE-SU-2022_2302-1
SUSE-SU-2022_2338-1
SUSE-SU-2022_2342-1
USN-5487-1
USN-5487-2
USN-5487-3

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu