CVE-2022-36760

Severity
9.0CRITICAL
EPSS
0.3%
top 47.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateOct 15

Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 2.2 | Impact: 6.0

Affected Packages4 packages

NVDapache/http_server2.4.02.4.55
Debianapache2< 2.4.56-1~deb11u1+3
Ubuntuapache2< 2.4.29-1ubuntu4.26+2

🔴Vulnerability Details

5
OSV
apache2 vulnerabilities2023-02-01
OSV
apache2 vulnerabilities2023-01-31
GHSA
GHSA-hwqh-57w6-xm49: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smu2023-01-17
OSV
CVE-2022-36760: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smu2023-01-17
CVEList
Apache HTTP Server: mod_proxy_ajp Possible request smuggling2023-01-17

📋Vendor Advisories

7
Oracle
Oracle Oracle Communications Risk Matrix: Platform (Apache HTTP Server) — CVE-2022-367602024-10-15
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache HTTP Server) — CVE-2022-367602023-04-15
Ubuntu
Apache HTTP Server vulnerabilities2023-02-01
Ubuntu
Apache HTTP Server vulnerabilities2023-01-31
Red Hat
httpd: mod_proxy_ajp: Possible request smuggling2023-01-17
CVE-2022-36760 (CRITICAL CVSS 9) | Inconsistent Interpretation of HTTP | cvebase.io