Lucene search

K
cvelistApacheCVELIST:CVE-2022-29404
HistoryJun 08, 2022 - 10:00 a.m.

CVE-2022-29404 Denial of service in mod_lua r:parsebody

2022-06-0810:00:52
CWE-770
apache
www.cve.org
1

8.6 High

AI Score

Confidence

High

0.032 Low

EPSS

Percentile

91.3%

In Apache HTTP Server 2.4.53 and earlier, a malicious request to a lua script that calls r:parsebody(0) may cause a denial of service due to no default limit on possible input size.

CNA Affected

[
  {
    "product": "Apache HTTP Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThanOrEqual": "2.4.53",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]