CVE-2022-28330

CWE-125Out-of-bounds Read6 documents6 sources
Severity
5.3MEDIUM
EPSS
0.6%
top 31.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateJun 10

Description

Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages3 packages

NVDapache/http_server2.4.53
CVEListV5apache_software_foundation/apache_http_serverApache HTTP Server2.4.53
Alpineapache2< 2.4.54-r0+10

🔴Vulnerability Details

3
GHSA
GHSA-w8xx-cjqj-c9jq: Apache HTTP Server 22022-06-10
OSV
CVE-2022-28330: Apache HTTP Server 22022-06-09
CVEList
read beyond bounds in mod_isapi2022-06-08

📋Vendor Advisories

2
Red Hat
httpd: mod_isapi: out-of-bounds read2022-06-08
Debian
CVE-2022-28330: apache2 - Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when con...2022
CVE-2022-28330 (MEDIUM CVSS 5.3) | Apache HTTP Server 2.4.53 and earli | cvebase.io