CVE-2022-30556: Information Disclosure in mod_lua with websockets
A flaw was found in the modlua module of httpd. The data returned by the wsread function may point past the end of the storage allocated for the buffer, resulting in information disclosure.
Other sources
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
Apache HTTP Server could allow a remote attacker to obtain sensitive information, caused by an error in modlua with websockets. An attacker could exploit this vulnerability to return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
— IBM
Affected Software
Remediation
Information
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2022-30556?
CVE-2022-30556 is a vulnerability in Apache HTTP Server that allows a remote attacker to obtain sensitive information.
How does CVE-2022-30556 affect Apache HTTP Server?
CVE-2022-30556 affects Apache HTTP Server by causing an error in mod_lua with websockets, allowing an attacker to return lengths to applications that point past the end of the allocated storage for the buffer.
What is the severity of CVE-2022-30556?
The severity of CVE-2022-30556 is high with a severity score of 7.5.
Which versions of Apache HTTP Server are affected by CVE-2022-30556?
Apache HTTP Server versions 2.4.53 and earlier are affected by CVE-2022-30556.
How can I mitigate CVE-2022-30556?
To mitigate CVE-2022-30556, it is recommended to update Apache HTTP Server to version 2.4.54.