Lucene search

K
cvelistApacheCVELIST:CVE-2022-22721
HistoryMar 14, 2022 - 10:15 a.m.

CVE-2022-22721 core: Possible buffer overflow with very large or unlimited LimitXMLRequestBody

2022-03-1410:15:40
CWE-190
apache
www.cve.org
3

9.9 High

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.7%

If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

CNA Affected

[
  {
    "product": "Apache HTTP Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "2.4.52",
        "status": "affected",
        "version": "Apache HTTP Server 2.4",
        "versionType": "custom"
      }
    ]
  }
]

References