PT-2022-6037 · Apache+7 · Apache Tomcat+7

Sam Shahsavar

·

Published

2022-10-11

·

Updated

2026-05-18

·

CVE-2022-42252

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.0 through 8.5.82 Apache Tomcat versions 9.0.0-M1 through 9.0.67 Apache Tomcat versions 10.0.0-M1 through 10.0.26 Apache Tomcat versions 10.1.0-M1 through 10.1.0
Description The issue is related to the implementation of the rejectIllegalHeader attribute in Apache Tomcat, which can lead to HTTP request smuggling attacks when the server is configured to ignore invalid HTTP headers and is located behind a reverse proxy that also fails to reject such requests. This can allow a remote attacker to send hidden HTTP requests. The rejectIllegalHeader setting, when set to false, allows Tomcat to process requests with invalid Content-Length headers, making the attack possible.
Recommendations For Apache Tomcat versions 8.5.0 through 8.5.82, update the configuration to set rejectIllegalHeader to true or upgrade to a version where this is the default. For Apache Tomcat versions 9.0.0-M1 through 9.0.67, ensure that rejectIllegalHeader is set to true and consider upgrading to a newer version. For Apache Tomcat versions 10.0.0-M1 through 10.0.26, set rejectIllegalHeader to true and consider upgrading. For Apache Tomcat versions 10.1.0-M1 through 10.1.0, set rejectIllegalHeader to true and consider upgrading to a version where this vulnerability is fixed. As a temporary workaround, consider restricting access to the server or disabling the processing of requests with invalid Content-Length headers until a patch is available.

Fix

DoS

RCE

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2023-8058
ALT-PU-2025-2379
ALT-PU-2025-9146
BDU:2022-07501
BIT-TOMCAT-2022-42252
CLEANSTART-2026-AJ47488
CLEANSTART-2026-AM95501
CLEANSTART-2026-CD66042
CLEANSTART-2026-GR86205
CLEANSTART-2026-KB11938
CLEANSTART-2026-MR27796
CLEANSTART-2026-RH10099
CLEANSTART-2026-RK94800
CLEANSTART-2026-SJ80413
CLEANSTART-2026-TN71701
CLEANSTART-2026-UZ56639
CLEANSTART-2026-XI02879
CLEANSTART-2026-XP03839
CLEANSTART-2026-XP58111
CVE-2022-42252
DLA-3384-1
DSA-5381-1
GHSA-P22X-G9PX-3945
MGASA-2023-0138
OESA-2023-1058
OPENSUSE-SU-2024:12534-1
OPENSUSE-SU-2024:13441-1
RHSA-2023:1663
ROSA-SA-2023-2258
SUSE-SU-2022:4193-1
SUSE-SU-2022:4221-1
SUSE-SU-2022:4257-1
SUSE-SU-2022:4303-1
SUSE-SU-2022_4193-1
SUSE-SU-2022_4303-1
SUSE-SU-2026:1058-1
USN-6880-1

Affected Products

Alt Linux
Apache Tomcat
Astra Linux
Confluence
Linuxmint
Red Os
Suse
Ubuntu