CVE-2022-36760

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to.  This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
9 CRITICAL
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
apachehttp_server
2.4.0 ≤
𝑥
< 2.4.55
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
apache2
bullseye
2.4.62-1~deb11u1
fixed
bullseye (security)
2.4.62-1~deb11u2
fixed
bookworm
2.4.62-1~deb12u1
fixed
bookworm (security)
2.4.62-1~deb12u2
fixed
sid
2.4.62-3
fixed
trixie
2.4.62-3
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
apache2
noble
Fixed 2.4.55-1ubuntu1
released
mantic
Fixed 2.4.55-1ubuntu1
released
lunar
Fixed 2.4.55-1ubuntu1
released
kinetic
Fixed 2.4.54-2ubuntu1.1
released
jammy
Fixed 2.4.52-1ubuntu4.3
released
focal
Fixed 2.4.41-4ubuntu3.13
released
bionic
Fixed 2.4.29-1ubuntu4.26
released
xenial
Fixed 2.4.18-2ubuntu3.17+esm8
released
trusty
needed