Lucene search

K
f5F5F5:K26314875
HistoryJun 23, 2022 - 12:00 a.m.

K26314875 : Apache vulnerability CVE-2022-26377

2022-06-2300:00:00
my.f5.com
43

8.6 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

79.3%

Security Advisory Description

Inconsistent Interpretation of HTTP Requests (‘HTTP Request Smuggling’) vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions. (CVE-2022-26377)

Impact

An attacker may be able to inject a crafted HTTP request into the server, bypassing internal security controls.