cbcvebase.
CVE-2022-22719
published 2022-03-14

CVE-2022-22719: A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52…

PriorityP260high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
69.80%
99.3th percentile
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.

Affected

19 ranges
VendorProductVersion rangeFixed in
apachehttp_server<= 2.4.52
apache_software_foundationapache_http_serverApache HTTP Server 2.4 – 2.4.52
applemac_os_x
applemacos< 10.15.710.15.7
applemacos>= 11.0 < 11.6.611.6.6
applemacos>= 12.0.0 < 12.412.4
applemacos_big_sur
applemacos_monterey
applesecurity_update_2022-004_catalina
debianapache2< apache2 2.4.53-1 (bookworm)apache2 2.4.53-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.53-1_on_cbl_mariner_2.0
msrccm1_httpd_2.4.53-1_on_cbl_mariner_1.0
oraclehttp_server
oraclehttp_server
oraclezfs_storage_appliance_kit

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability resides specifically in the mod_lua module's parsebody function — target detection at crafted request bodies sent to servers with mod_lua enabled
  • Apache HTTP Server versions 2.4.52 and earlier are affected; alert on these version strings in server banners or software inventory
  • Monitor for Apache httpd process crashes (denial of service) originating from mod_lua request body processing — unexpected httpd worker crashes may indicate exploitation attempts
  • The highest impact is to availability (DoS); correlate sudden httpd worker crashes with inbound HTTP requests containing unusual or malformed body content
  • ·httpd as shipped with Red Hat Enterprise Linux 6 is NOT affected because it does not ship mod_lua — scope detection efforts accordingly
  • ·Disabling mod_lua and restarting httpd is a valid mitigation — verify mod_lua is loaded before treating a host as vulnerable
  • ·The vulnerability is triggered via the r:parsebody Lua API — only endpoints that invoke parsebody in Lua scripts are exploitable attack surfaces

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.