cbcvebase.
CVE-2022-22728
published 2022-08-25

CVE-2022-22728: A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a…

PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
4.71%
90.8th percentile
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

Affected

10 ranges
VendorProductVersion rangeFixed in
apachelibapreq2<= 2.16
apachelibapreq2>= 0 < 2.13-7+deb11u12.13-7+deb11u1
apachelibapreq2>= 0 < 2.17-12.17-1
apachelibapreq2>= 0 < 2.17-12.17-1
apache_software_foundationlibapreq2unspecified – 2.16
debiandebian_linux
debianlibapreq2< libapreq2 2.13-7+deb11u1 (bullseye)libapreq2 2.13-7+deb11u1 (bullseye)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora

CVSS provenance

nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.