CVE-2022-37436

Updated: 2025-08-20 03:07:32.852401

Description:

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x MEDIUM 5.3

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU httpd 2.4.53 5.3 MEDIUM Ignored 2023-11-08 04:07:59 Exploitation requires Apache httpd to be acting as a reverse proxy (mod_proxy) and for the upstream ...
CentOS 6 ELS httpd 2.2.15 5.3 MEDIUM Ignored 2023-01-25 04:03:31 Ignored due to low severity
CentOS 7 ELS httpd 2.4.6 5.3 MEDIUM Ignored 2023-09-19 09:30:21 Ignored due to low severity
CentOS 8.4 ELS httpd 2.4.37 5.3 MEDIUM Released CLSA-2023:1678135884 2023-03-06 16:05:00
CentOS 8.5 ELS httpd 2.4.37 5.3 MEDIUM Released CLSA-2023:1678136294 2023-03-06 16:05:00
CloudLinux 6 ELS httpd 2.2.15 5.3 MEDIUM Ignored 2023-01-25 04:03:31 Ignored due to low severity
Oracle Linux 6 ELS httpd 2.2.15 5.3 MEDIUM Ignored 2023-01-25 04:03:32 Ignored due to low severity
Ubuntu 16.04 ELS apache2 2.4.18 5.3 MEDIUM Released CLSA-2023:1675985294 2023-02-09 19:59:12
Ubuntu 18.04 ELS apache2 2.4.29 5.3 MEDIUM Already Fixed 2023-11-06 08:42:55