CVE-2022-42252
published 2022-11-01CVE-2022-42252: If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
1.45%
70.4th percentile
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.0.0 < 10.0.27 | 10.0.27 |
| apache | tomcat | >= 10.1.0 < 10.1.1 | 10.1.1 |
| apache | tomcat | >= 8.5.0 < 8.5.83 | 8.5.83 |
| apache | tomcat | >= 9.0.0 < 9.0.68 | 9.0.68 |
| apache_software_foundation | apache_tomcat | 10.0.0-M1 – 10.0.26 | — |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.0 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.82 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.67 | — |
| atlassian | jira_software | — | — |
| debian | tomcat9 | < tomcat9 9.0.68-1 (bookworm) | tomcat9 9.0.68-1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerability
vendor_ubuntu·2024-07-09
CVE-2022-42252 Tomcat vulnerability
Title: Tomcat vulnerability
Summary: Tomcat could allow unintended access to network services.
Sam Shahsavar discovered that Apache Tomcat did not properly reject
HTTP requests with an invalid Content-Length header. A remote attacker
could possibly use this issue to perform HTTP request smuggling attacks.
Instructions: In general, a standard system update will make all the necessary changes.
Atlassian
CVE-2022-42252: Request Smuggling org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center and Server
vendor_atlassian·2024-01-16·CVSS 7.5
CVE-2022-42252 [HIGH] CVE-2022-42252: Request Smuggling org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center and Server
CVE-2022-42252: Request Smuggling org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center and Server
Request Smuggling org.apache.tomcat:tomcat-coyote Dependency in Jira Software Data Center and Server
CVE: CVE-2022-42252
Severity: HIGH
Affected products: Jira Software
Oracle
Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) — CVE-2022-42252
vendor_oracle·2023-04-15·CVSS 7.5
CVE-2022-42252 [HIGH] Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) — CVE-2022-42252
Oracle Oracle Communications Risk Matrix: BEServer (Apache Tomcat) vulnerability
CVE: CVE-2022-42252
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) — CVE-2022-42252
vendor_oracle·2023-01-15·CVSS 7.5
CVE-2022-42252 [HIGH] Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) — CVE-2022-42252
Oracle Oracle Communications Applications Risk Matrix: DBPlugin (Apache Tomcat) vulnerability
CVE: CVE-2022-42252
CVSS: 7.5
Protocol: HTTPS
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Red Hat
tomcat: request smuggling
vendor_redhat·2022-10-31·CVSS 7.5
CVE-2022-42252 [HIGH] CWE-444 tomcat: request smuggling
tomcat: request smuggling
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
A flaw was found in Apache Tomcat. If the server is configured to ignore invalid HTTP headers, the server does not reject a request containing an invalid content-length header, making it vulnerable to a request smuggling attack.
Statement: Red Hat Satellite does not include the affected Apache Tomcat, however, Tomcat is shippe
Debian
CVE-2022-42252: tomcat9 - If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10...
vendor_debian·2022·CVSS 7.5
CVE-2022-42252 [HIGH] CVE-2022-42252: tomcat9 - If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10...
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
Scope: local
bookworm: resolved (fixed in 9.0.68-1)
bullseye: resolved (fixed in 9.0.43-2~deb11u6)
forky: resolved (fixed in 9.0.68-1)
sid: resolved (fixed in 9.0.68-1)
trixie: resolved (fixed in 9.0.68-1)
Apache
Apache tomcat: CVE-2022-42252
vendor_apache·CVSS 7.5
CVE-2022-42252 [HIGH] Apache tomcat: CVE-2022-42252
Apache tomcat: CVE-2022-42252
If Tomcat was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header. This was fixed with commit a1c07906 . This issue was reported to the Apache Tomcat Security team on 29 September 2022. The issue was made public on 31 October 2022. Affects: 8.5.0 to 8.5.82 2022-08-13 Fixed in Apache Tomcat 8.5.82 Low: Apache Tomcat XSS in examples web application
GHSA
Apache Tomcat may reject request containing invalid Content-Length header
ghsa·2022-11-01
CVE-2022-42252 [HIGH] CWE-20 Apache Tomcat may reject request containing invalid Content-Length header
Apache Tomcat may reject request containing invalid Content-Length header
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
OSV
Apache Tomcat may reject request containing invalid Content-Length header
osv·2022-11-01
CVE-2022-42252 [HIGH] Apache Tomcat may reject request containing invalid Content-Length header
Apache Tomcat may reject request containing invalid Content-Length header
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
OSV
CVE-2022-42252: If Apache Tomcat 8
osv·2022-11-01·CVSS 7.5
CVE-2022-42252 [HIGH] CVE-2022-42252: If Apache Tomcat 8
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-01
Published