cbcvebase.
CVE-2022-37436
published 2023-01-17

CVE-2022-37436: Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

Affected

11 ranges
VendorProductVersion rangeFixed in
apachehttp_server< 2.4.552.4.55
apachehttpd
apache_software_foundationapache_http_server< 2.4.552.4.55
debianapache2< apache2 2.4.55-1 (bookworm)apache2 2.4.55-1 (bookworm)
msrcazl3_mod_http2_2.0.29-3_on_azure_linux_3.0
msrccbl2_httpd_2.4.55-1_on_cbl_mariner_2.0
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrccm1_httpd_2.4.55-1_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv7.5HIGH