First published: Tue Jan 17 2023(Updated: )
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
Credit: security@apache.org security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache HTTP server | >=2.4.0<2.4.55 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-36760.
The severity of CVE-2022-36760 is critical.
Apache HTTP Server version 2.4.54 and prior versions are affected by CVE-2022-36760.
An attacker can exploit CVE-2022-36760 by smuggling requests to the AJP server that Apache HTTP Server forwards requests to.
To fix CVE-2022-36760, update Apache HTTP Server to version 2.4.55 or higher.