CVE-2022-29404

Updated: 2025-08-20 01:43:18.814007

Description:

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU httpd 2.4.53 7.5 HIGH Already Fixed 2023-11-08 08:35:59
CentOS 6 ELS httpd 2.2.15 7.5 HIGH Not Vulnerable 2023-06-28 14:12:19
CentOS 7 ELS httpd 2.4.6 7.5 HIGH Released CLSA-2023:1696536930 2023-10-05 17:08:32
CentOS 8.4 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2022:1668705928 2022-11-17 13:25:01
CentOS 8.5 ELS httpd 2.4.37 7.5 HIGH Released CLSA-2022:1668706027 2022-11-17 13:25:01
CloudLinux 6 ELS httpd 2.2.15 7.5 HIGH Not Vulnerable 2023-06-28 14:12:19
CloudLinux 7 ELS httpd 2.4.6 7.5 HIGH Released CLSA-2024:1726078096 2024-09-18 12:25:29
Oracle Linux 6 ELS httpd 2.2.15 7.5 HIGH Not Vulnerable 2023-06-28 14:12:19
Ubuntu 16.04 ELS apache2 2.4.18 7.5 HIGH Released CLSA-2023:1689009164 2023-07-10 14:12:13
Ubuntu 18.04 ELS apache2 2.4.29 7.5 HIGH Already Fixed 2023-06-02 09:10:39