CVE-2022-30780: High severity fipsasp fipscms light vulnerability
Lighttpd 1.4.56 through 1.4.58 allows a remote attacker to cause a denial of service (CPU consumption from stuck connections) because connectionreadheadermore in connections.c has a typo that disrupts use of multiple read operations on large headers.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-30780?
CVE-2022-30780 is a vulnerability in Lighttpd versions 1.4.56 through 1.4.58 that allows a remote attacker to cause a denial of service by consuming excessive CPU resources through stuck connections.
How does CVE-2022-30780 impact Lighttpd?
CVE-2022-30780 affects Lighttpd by disrupting the use of multiple read operations on large headers, leading to excessive CPU consumption and a denial of service.
What is the severity of CVE-2022-30780?
CVE-2022-30780 has a severity rating of 7.5, classified as high.
Which versions of Lighttpd are affected by CVE-2022-30780?
Lighttpd versions 1.4.56, 1.4.57, and 1.4.58 are affected by CVE-2022-30780.
Are there any fixes or patches available for CVE-2022-30780?
At the time of writing, there are no official patches or fixes available for CVE-2022-30780. It is recommended to update to a non-vulnerable version when one becomes available.