PT-2022-3372 · Apache+10 · Apache Http Server+10

Régis Leroy

·

Published

2022-06-08

·

Updated

2026-03-10

·

CVE-2022-31813

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.53 and earlier
Description The issue is related to the mod proxy module in Apache HTTP Server, which may not properly handle X-Forwarded-* headers based on the client-side Connection header hop-by-hop mechanism. This could allow a remote attacker to bypass IP-based authentication on the origin server or application.
Recommendations For Apache HTTP Server versions 2.4.53 and earlier, consider updating to a version that includes the fix for this issue, as the current version may not send the X-Forwarded-* headers to the origin server based on the client-side Connection header hop-by-hop mechanism, potentially allowing IP-based authentication bypass. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficient Verification of Data Authenticity

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7647
ALSA-2022:8067
ALT-PU-2022-2087
ALT-PU-2022-2093
ALT-PU-2022-2095
ALT-PU-2023-1260
BDU:2022-04141
BIT-APACHE-2022-31813
CESA-2022_7647
CVE-2022-31813
MGASA-2022-0228
OESA-2022-1718
OPENSUSE-SU-2022_2302-1
OPENSUSE-SU-2022_2342-1
OPENSUSE-SU-2024:12142-1
RHSA-2022:6753
RHSA-2022:7647
RHSA-2022:8067
RHSA-2022:8840
RHSA-2022_7647
RHSA-2022_8067
RLSA-2022:7647
RLSA-2022:8067
ROSA-SA-2024-2515
SUSE-SU-2022:2099-1
SUSE-SU-2022:2101-1
SUSE-SU-2022:2302-1
SUSE-SU-2022:2338-1
SUSE-SU-2022:2342-1
USN-5487-1
USN-5487-2
USN-5487-3

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu