PT-2022-3372 · Apache+10 · Apache Http Server+10
Régis Leroy
·
Published
2022-06-08
·
Updated
2026-03-10
·
CVE-2022-31813
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Apache HTTP Server versions 2.4.53 and earlier
Description
The issue is related to the mod proxy module in Apache HTTP Server, which may not properly handle X-Forwarded-* headers based on the client-side Connection header hop-by-hop mechanism. This could allow a remote attacker to bypass IP-based authentication on the origin server or application.
Recommendations
For Apache HTTP Server versions 2.4.53 and earlier, consider updating to a version that includes the fix for this issue, as the current version may not send the X-Forwarded-* headers to the origin server based on the client-side Connection header hop-by-hop mechanism, potentially allowing IP-based authentication bypass.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu