CVE-2022-36760

Updated: 2023-01-30 19:21:11.891366

Description:

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0
CVSS Version 3.x CRITICAL 9

Status

OS name Project name Version Score Severity Status Errata Last updated
CentOS 6 ELS httpd 2.2.15 9 CRITICAL Released CLSA-2023:1675111939 2023-02-16 14:30:31
CentOS 8.4 ELS httpd 2.4.37 9 CRITICAL Released CLSA-2023:1675111607 2023-01-30 16:03:31
CentOS 8.5 ELS httpd 2.4.37 9 CRITICAL Released CLSA-2023:1675111708 2023-01-30 16:03:31
CloudLinux 6 ELS httpd 2.2.15 9 CRITICAL Released CLSA-2023:1675111836 2023-02-16 14:30:31
Oracle Linux 6 ELS httpd 2.2.15 9 CRITICAL Released CLSA-2023:1675111450 2023-01-30 16:03:23
Ubuntu 16.04 ELS apache2 2.4.18 9 CRITICAL Released CLSA-2023:1675111279 2023-01-30 16:03:31
Ubuntu 18.04 ELS apache2 2.4.29 9 CRITICAL Needs Triage 2023-03-01 16:01:25