CVE-2022-23943
published 2022-03-14CVE-2022-23943: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue…
PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
50.40%
98.8th percentile
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | >= 2.4.0 < 2.4.53 | 2.4.53 |
| apache | httpd | — | — |
| apache_software_foundation | apache_http_server | 2.4 – 2.4.52 | — |
| debian | apache2 | < apache2 2.4.53-1 (bookworm) | apache2 2.4.53-1 (bookworm) |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| msrc | cbl2_httpd_2.4.53-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_httpd_2.4.53-1_on_cbl_mariner_1.0 | — | — |
| oracle | http_server | — | — |
| oracle | http_server | — | — |
| oracle | zfs_storage_appliance_kit | — | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Vulnerability resides in the mod_sed module of Apache HTTP Server; detect exploitation attempts targeting mod_sed request processing (heap out-of-bounds read/write via attacker-supplied data) ↗
- →Affected versions are Apache HTTP Server 2.4.52 and prior (2.4.x branch); flag any server still running <= 2.4.52 with mod_sed enabled as a high-priority finding ↗
- →Fixed in Apache HTTP Server 2.4.53 (SVN revisions r1898695 and r1898772 in 2.4.x); use version detection to confirm patched state ↗
- →mod_sed is disabled by default on RHEL 7 and 8; actively check whether mod_sed is loaded (e.g., via 'httpd -M | grep sed') to confirm exposure before triaging ↗
- →Exploitation is remotely possible over HTTPS with no authentication; prioritise internet-facing Apache instances with mod_sed loaded for immediate patching/detection ↗
- ·mod_sed must be actively loaded for the vulnerability to be exploitable; instances where mod_sed is absent or disabled are not affected ↗
- ·Apache HTTP Server 2.x packages shipped with RHEL 6 are not affected because mod_sed was only introduced in httpd 2.3+ ↗
- ·Disabling mod_sed and restarting httpd is a valid interim mitigation where patching to 2.4.53 is not immediately possible ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_apache9.8HIGH
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
vendor_paloalto·2024-04-10·CVSS 9.8
CVE-2015-5739 [CRITICAL] PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
PAN-SA-2024-0004 Informational Bulletin: OSS CVEs fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2015-5739 This CVE is fixed in PAN-OS 11.0.4, and all later PAN-OS versions. CVE-2016-10228 This CVE is fixed in PAN-OS 11.1.3, and all later PAN-OS versions. CVE-2017-8923 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2017-9120 This CVE is fixed in PAN-OS 10.2.8, 11.0.3, and all later PAN-OS versions. CVE-2018-25009 This CVE is fixed in PAN-OS 10.2.8, 11.0.4, 11.1.3, and all later PAN-OS versions. CVE-2
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) — CVE-2022-23943
vendor_oracle·2022-10-15·CVSS 9.8
CVE-2022-23943 [CRITICAL] Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) — CVE-2022-23943
Oracle Oracle Fusion Middleware Risk Matrix: SSL Module (Apache HTTP Server) vulnerability
CVE: CVE-2022-23943
CVSS: 9.8
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
CISA ICS
Mitsubishi Electric MELSOFT iQ AppPortal
cisa_ics·2022-05-12·CVSS 5.5
[MEDIUM] Mitsubishi Electric MELSOFT iQ AppPortal
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Mitsubishi Electric MELSOFT iQ AppPortal
Last RevisedMay 12, 2022
Alert CodeICSA-22-132-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Mitsubishi Electric
- Equipment: MELSOFT iQ AppPortal
- Vulnerabilities: Missing Authorization, Out-of-bounds Write, NULL Pointer Dereference, Classic Buffer Overflow, HTTP Request Smuggling, Infinite Loop
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in a denial-of-service condition, malicious program execution, information disclosure, informa
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2022-03-17·CVSS 7.5
CVE-2022-22721 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
USN-5333-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Chamal De Silva discovered that the Apache HTTP Server mod_lua module
incorrectly handled certain crafted request bodies. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service. (CVE-2022-22719)
James Kettle discovered that the Apache HTTP Server incorrectly closed
inbound connection when certain errors are encountered. A remote attacker
could possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-22720)
It was discovered that the Ap
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2022-03-17·CVSS 7.5
CVE-2022-22719 [HIGH] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Chamal De Silva discovered that the Apache HTTP Server mod_lua module
incorrectly handled certain crafted request bodies. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service. (CVE-2022-22719)
James Kettle discovered that the Apache HTTP Server incorrectly closed
inbound connection when certain errors are encountered. A remote attacker
could possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-22720)
It was discovered that the Apache HTTP Server incorrectly handled large
LimitXMLRequestBody settings on certain platforms. In certain
configurations, a remote attacker could use this issue to cause t
Red Hat
httpd: mod_sed: Read/write beyond bounds
vendor_redhat·2022-03-14·CVSS 9.8
CVE-2022-23943 [CRITICAL] CWE-787 httpd: mod_sed: Read/write beyond bounds
httpd: mod_sed: Read/write beyond bounds
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
An out-of-bounds read/write vulnerability was found in the mod_sed module of httpd. This flaw allows an attacker to overwrite the memory of an httpd instance that is using mod_sed with data provided by the attacker.
Statement: The `mod_sed` module is disabled by default on Red Hat Enterprise Linux 7 and 8. For this reason, the flaw has been rated as having a security impact of Moderate. The httpd package as shipped with Red Hat Enterprise Linux 6 is not affected by this flaw because the `mod_sed` module is available only in
Microsoft
mod_sed: Read/write beyond bounds
vendor_msrc·2022-03-08·CVSS 9.8
CVE-2022-23943 [CRITICAL] CWE-787 mod_sed: Read/write beyond bounds
mod_sed: Read/write beyond bounds
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us
Debian
CVE-2022-23943: apache2 - Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an att...
vendor_debian·2022·CVSS 9.8
CVE-2022-23943 [CRITICAL] CVE-2022-23943: apache2 - Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an att...
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
Scope: local
bookworm: resolved (fixed in 2.4.53-1)
bullseye: resolved (fixed in 2.4.53-1~deb11u1)
forky: resolved (fixed in 2.4.53-1)
sid: resolved (fixed in 2.4.53-1)
trixie: resolved (fixed in 2.4.53-1)
Apache
Apache httpd: CVE-2022-23943
vendor_apache·CVSS 9.8
CVE-2022-23943 [HIGH] Apache httpd: CVE-2022-23943
Apache httpd: CVE-2022-23943
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions. Acknowledgements: Ronald Crane (Zippenhop LLC) Reported to security team 2022-01-13 fixed by r1898695, r1898772 in 2.4.x 2022-03-09 Update 2.4.53 released 2022-03-14 Affects <=2.4.52
Severity: high
Affected versions: 2.4.52
OSV
apache2 vulnerabilities
osv·2022-03-17·CVSS 7.5
CVE-2022-22719 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
Chamal De Silva discovered that the Apache HTTP Server mod_lua module
incorrectly handled certain crafted request bodies. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service. (CVE-2022-22719)
James Kettle discovered that the Apache HTTP Server incorrectly closed
inbound connection when certain errors are encountered. A remote attacker
could possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-22720)
It was discovered that the Apache HTTP Server incorrectly handled large
LimitXMLRequestBody settings on certain platforms. In certain
configurations, a remote attacker could use this issue to cause the server
to crash, resulting in a denial of service, or possibly execute arbitrary
co
OSV
apache2 vulnerabilities
osv·2022-03-17·CVSS 7.5
CVE-2022-22719 [HIGH] apache2 vulnerabilities
apache2 vulnerabilities
USN-5333-1 fixed several vulnerabilities in Apache. This update provides
the corresponding update for Ubuntu 14.04 ESM and Ubuntu 16.04 ESM.
Original advisory details:
Chamal De Silva discovered that the Apache HTTP Server mod_lua module
incorrectly handled certain crafted request bodies. A remote attacker could
possibly use this issue to cause the server to crash, resulting in a denial
of service. (CVE-2022-22719)
James Kettle discovered that the Apache HTTP Server incorrectly closed
inbound connection when certain errors are encountered. A remote attacker
could possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2022-22720)
It was discovered that the Apache HTTP Server incorrectly handled large
LimitXMLRequestBody settings on certain pla
GHSA
GHSA-778r-vp3x-2f8c: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data
ghsa_unreviewed·2022-03-15
CVE-2022-23943 [CRITICAL] CWE-190 GHSA-778r-vp3x-2f8c: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
OSV
CVE-2022-23943: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data
osv·2022-03-14·CVSS 9.8
CVE-2022-23943 [CRITICAL] CVE-2022-23943: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.
No detection rules found.
No public exploits indexed.
arXiv
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
arxiv_fulltext·2025-06-30·CVSS 9.8
[CRITICAL] Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
titlepage
*1cm
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure \ 1cm]
Alessio Di Santo ([email protected])
Università degli Studi dell’Aquila, L’Aquila, Abruzzo, Italy
Date: July 1,2025
!60 "Non videmus ea quae mox futura sunt" \ 0.5cm]
!60(We do not see the things that will soon be) — Marcus Tullius Cicero
titlepage
## Executive Summary
This analysis focuses on a single Azure-hosted Virtual Machine at 52.230.23[.]114 that the adversary converted into an all-in-one delivery, staging and Command-and-Control node. The host advertises an out-of-date Apache 2.4.52 instance whose open directory exposes phishing lures, PowerShell loaders, Reflective Shell-Code, compiled Havoc Demon implants and a toolbox of lateral-movement binaries; the same server als
Checkpoint
25th April – Threat Intelligence Report
blogs_checkpoint·2022-04-25
CVE-2021-34473 25th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 25th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 25th April, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Russian state-sponsored APT actor Gamaredon (aka Shuckworm) has targeted Ukrainian organizations using at least four different variants of the Pterodo backdoor, likely to maintain persistence on infected computers. The group has been performing cyber-espionage campaigns in Ukraine since at least 2014.
Researchers have found
HackerOne
Read and write beyond bounds in mod_sed
hackerone·2022-04-14
[HIGH] Read and write beyond bounds in mod_sed
Read and write beyond bounds in mod_sed
This CVE consists of several bugs in mod_sed, where overflows, truncation, uses after free and a logic error can allow a remote, unauthenticated attacker to read and/or write heap locations beyond bounds. See https://github.com/apache/httpd/commit/943f57b336f264d77e5b780c82ab73daf3d14deb and https://github.com/apache/httpd/commit/e266bd09c313a668d7cca17a8b096d189148be49 for the commits that fixed the bugs. Attached are my reports to the httpd team; email me if you need additional information.
----
1. Use-after-free and truncation/overflows causing read/write beyond bounds:
```
Greetings. I have discovered a use-after-free bug in sed1.c that causes a read and/or write beyond bounds.
The bug is that dosub() (modules/filters/sed1.c) does not update |
http://www.openwall.com/lists/oss-security/2022/03/14/1https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20220321-0001/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.tenable.com/security/tns-2022-08https://www.tenable.com/security/tns-2022-09http://www.openwall.com/lists/oss-security/2022/03/14/1https://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2022/03/msg00033.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RGWILBORT67SHMSLYSQZG2NMXGCMPUZO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X73C35MMMZGBVPQQCH7LQZUMYZNQA5FO/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z7H26WJ6TPKNWV3QKY4BHKUKQVUTZJTD/https://security.gentoo.org/glsa/202208-20https://security.netapp.com/advisory/ntap-20220321-0001/https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.tenable.com/security/tns-2022-08https://www.tenable.com/security/tns-2022-09
2022-03-14
Published