CVE-2022-26377

Description

Inconsistent Interpretation of HTTP Requests (HTTP Request Smuggling) vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
39.88

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-26377 are fixed in Apache 2.4.54Windows
Multiple vulnerabilities are fixed in IBM HTTP 8.5.5.23Windows
Multiple vulnerabilities are fixed in IBM HTTP 9.0.5.13Windows
Multiple Vulnerabilities are affected in IBM Tivoli Monitoring 6.3.0Windows
Multiple Vulnerabilities are affected in IBM Aspera Faspex 4.4.2Windows
Apache HTTP server (USN-5487-1) apache2_2.4.52-1ubuntu4.1_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.52-1ubuntu4.1_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.29-1ubuntu4.24_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.29-1ubuntu4.24_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.41-4ubuntu3.12_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.41-4ubuntu3.12_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.48-3.1ubuntu3.5_i386.debLinux
Apache HTTP server (USN-5487-1) apache2_2.4.48-3.1ubuntu3.5_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.6_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.6_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.29-1ubuntu4.24_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.29-1ubuntu4.24_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.14_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.14_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.48-3.1ubuntu3.5_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.48-3.1ubuntu3.5_amd64.debLinux
Apache HTTP server (USN-5487-3) apache2_2.4.29-1ubuntu4.25_i386.debLinux
Apache HTTP server (USN-5487-3) apache2_2.4.29-1ubuntu4.25_amd64.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.27_i386.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.27_amd64.debLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-core-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-debugsource-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-devel-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-filesystem-2.4.53-7.el9.noarch.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-manual-2.4.53-7.el9.noarch.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update httpd-tools-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_ldap-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_lua-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_proxy_html-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_session-2.4.53-7.el9.x86_64.rpmLinux
(RHSA-2022:8067) httpd security, bug fix, and enhancement update mod_ssl-2.4.53-7.el9.x86_64.rpmLinux
SUSE-SU-2022:2342-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) apache2-utils-debuginfo-2.4.51-150200.3.48.1.x86_64.rpmLinux
SUSE-SU-2022:2342-1(SUSE Linux Enterprise Module for Basesystem 15-SP3 ) apache2-prefork-debuginfo-2.4.51-150200.3.48.1.x86_64.rpmLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.1_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.52-1ubuntu4.1_amd64.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.12_i386.debLinux
Apache HTTP server (USN-5487-1) apache2-bin_2.4.41-4ubuntu3.12_amd64.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.25_i386.debLinux
Apache HTTP server (USN-5487-3) apache2-bin_2.4.29-1ubuntu4.25_amd64.debLinux
Inconsistent Interpretation of HTTP Requests (HTTP Request/Response Smuggling) Vulnerability (CVE-2022-26377)NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234