cbcvebase.
CVE-2022-23943
published 2022-03-14

CVE-2022-23943: Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue…

PriorityP272critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
50.40%
98.8th percentile
Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

Affected

14 ranges
VendorProductVersion rangeFixed in
apachehttp_server>= 2.4.0 < 2.4.532.4.53
apachehttpd
apache_software_foundationapache_http_server2.4 – 2.4.52
debianapache2< apache2 2.4.53-1 (bookworm)apache2 2.4.53-1 (bookworm)
debiandebian_linux
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
msrccbl2_httpd_2.4.53-1_on_cbl_mariner_2.0
msrccm1_httpd_2.4.53-1_on_cbl_mariner_1.0
oraclehttp_server
oraclehttp_server
oraclezfs_storage_appliance_kit
paloaltopan-os

Detection & IOCsextracted from sources · hover to see the quote

  • Vulnerability resides in the mod_sed module of Apache HTTP Server; detect exploitation attempts targeting mod_sed request processing (heap out-of-bounds read/write via attacker-supplied data)
  • Affected versions are Apache HTTP Server 2.4.52 and prior (2.4.x branch); flag any server still running <= 2.4.52 with mod_sed enabled as a high-priority finding
  • Fixed in Apache HTTP Server 2.4.53 (SVN revisions r1898695 and r1898772 in 2.4.x); use version detection to confirm patched state
  • mod_sed is disabled by default on RHEL 7 and 8; actively check whether mod_sed is loaded (e.g., via 'httpd -M | grep sed') to confirm exposure before triaging
  • Exploitation is remotely possible over HTTPS with no authentication; prioritise internet-facing Apache instances with mod_sed loaded for immediate patching/detection
  • ·mod_sed must be actively loaded for the vulnerability to be exploitable; instances where mod_sed is absent or disabled are not affected
  • ·Apache HTTP Server 2.x packages shipped with RHEL 6 are not affected because mod_sed was only introduced in httpd 2.3+
  • ·Disabling mod_sed and restarting httpd is a valid interim mitigation where patching to 2.4.53 is not immediately possible

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_apache9.8HIGH
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.