CVE-2022-37436: Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.5.1.117.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.8.4 - Upgrade
Upgrade
redhat/httpdto a version that resolves this vulnerability.Fixed in 2.4.55
Event History
Frequently Asked Questions
What is CVE-2022-37436?
CVE-2022-37436 is a vulnerability in Apache HTTP Server prior to version 2.4.55 that allows a malicious backend to truncate response headers, resulting in some headers being incorporated into the response body.
How does CVE-2022-37436 affect Apache HTTP Server?
CVE-2022-37436 affects Apache HTTP Server versions prior to 2.4.55.
What is the severity of CVE-2022-37436?
CVE-2022-37436 has a severity of medium with a CVSS score of 5.3.
What is the CWE ID of CVE-2022-37436?
CVE-2022-37436 is associated with CWE IDs 113 and 436.
How can I fix CVE-2022-37436?
To fix CVE-2022-37436, upgrade your Apache HTTP Server to version 2.4.55 or later.