Lucene search

K
cvelistApacheCVELIST:CVE-2022-37436
HistoryJan 17, 2023 - 7:12 p.m.

CVE-2022-37436 Apache HTTP Server: mod_proxy prior to 2.4.55 allows a backend to trigger HTTP response splitting

2023-01-1719:12:59
CWE-113
apache
www.cve.org
1
apache
http server
mod_proxy
vulnerability
response splitting

7.4 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

36.4%

Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Apache HTTP Server",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "lessThan": "2.4.55",
        "status": "affected",
        "version": "0",
        "versionType": "semver"
      }
    ]
  }
]