Lucene search

K
osvGoogleOSV:CVE-2022-28614
HistoryJun 09, 2022 - 5:15 p.m.

CVE-2022-28614

2022-06-0917:15:09
Google
osv.dev
13
cve-2022-28614
apache http server
unintended memory read
mod_lua
software bug

AI Score

9.3

Confidence

High

EPSS

0.003

Percentile

71.9%

The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the ‘ap_rputs’ function and may pass it a very large (INT_MAX or larger) string must be compiled against current headers to resolve the issue.