PT-2022-3378 · Apache+10 · Apache Http Server+10

Ronald Crane

·

Published

2022-06-08

·

Updated

2025-05-15

·

CVE-2022-29404

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.53 and earlier
Description The issue is related to the mod lua module in Apache HTTP Server, where a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size. This can be exploited by a remote attacker by sending a specially crafted HTTP request, potentially leading to a denial of service. The vulnerability is associated with insufficient input validation when handling HTTP requests to a lua script that invokes r:parsebody(0).
Recommendations For Apache HTTP Server versions 2.4.53 and earlier, as a temporary workaround, consider disabling the r:parsebody(0) function in lua scripts until a patch is available. Restrict access to lua scripts that invoke r:parsebody(0) to minimize the risk of exploitation. Avoid using the r:parsebody(0) function in HTTP requests to affected lua scripts until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

ALSA-2022:7647
ALSA-2022:8067
ALT-PU-2022-2087
ALT-PU-2022-2093
ALT-PU-2022-2095
ALT-PU-2023-1260
BDU:2022-04147
BIT-APACHE-2022-29404
CESA-2022_7647
CVE-2022-29404
MGASA-2022-0228
OESA-2022-1718
OPENSUSE-SU-2022_2302-1
OPENSUSE-SU-2022_2342-1
OPENSUSE-SU-2024:12142-1
RHSA-2022:6753
RHSA-2022:7647
RHSA-2022:8067
RHSA-2022_7647
RHSA-2022_8067
RLSA-2022:7647
RLSA-2022:8067
SUSE-SU-2022:2099-1
SUSE-SU-2022:2101-1
SUSE-SU-2022:2302-1
SUSE-SU-2022:2338-1
SUSE-SU-2022:2342-1
USN-5487-1
USN-5487-2
USN-5487-3

Affected Products

Alt Linux
Almalinux
Apache Http Server
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu