Lucene search

K
cve[email protected]CVE-2022-22728
HistoryAug 25, 2022 - 3:15 p.m.

CVE-2022-22728

2022-08-2515:15:08
CWE-120
web.nvd.nist.gov
44
14
cve-2022-22728
apache
libapreq2
buffer overflow
denial of service
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%

A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.

Affected configurations

Vulners
NVD
Node
apachelibapreq2Range2.16
CPENameOperatorVersion
apache:libapreq2apache libapreq2le2.16

CNA Affected

[
  {
    "vendor": "Apache Software Foundation",
    "product": "libapreq2",
    "versions": [
      {
        "version": "unspecified",
        "lessThanOrEqual": "2.16",
        "status": "affected",
        "versionType": "custom"
      }
    ]
  }
]

References

Social References

More

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.4 High

AI Score

Confidence

High

0.029 Low

EPSS

Percentile

90.8%