Apache HTTP Server: mod_proxy_ajp Possible request smuggling
CVE-2022-36760

9CRITICAL

Key Information:

Vendor
Apache
Vendor
CVE Published:
17 January 2023

Summary

A vulnerability exists in the mod_proxy_ajp module of the Apache HTTP Server that allows attackers to exploit inconsistent interpretation of HTTP requests. By smuggling crafted requests intended for the backend AJP server, an attacker can bypass security measures and potentially execute unauthorized commands. This issue primarily affects Apache HTTP Server versions 2.4.54 and earlier, highlighting the need for immediate updates and security measures to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Apache HTTP Server 2.4 <= 2.4.54

References

EPSS Score

3% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

ZeddYu_Lu from Qi'anxin Research Institute of Legendsec at Qi'anxin Group
.