5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
0.006 Low
EPSS
Percentile
79.3%
Inconsistent Interpretation of HTTP Requests (‘HTTP Request Smuggling’)
vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to
smuggle requests to the AJP server it forwards requests to. This issue
affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior
versions.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
ubuntu | 18.04 | noarch | apache2 | < 2.4.29-1ubuntu4.24 | UNKNOWN |
ubuntu | 20.04 | noarch | apache2 | < 2.4.41-4ubuntu3.12 | UNKNOWN |
ubuntu | 21.10 | noarch | apache2 | < 2.4.48-3.1ubuntu3.5 | UNKNOWN |
ubuntu | 22.04 | noarch | apache2 | < 2.4.52-1ubuntu4.1 | UNKNOWN |
ubuntu | 22.10 | noarch | apache2 | < 2.4.54-2ubuntu1 | UNKNOWN |
ubuntu | 14.04 | noarch | apache2 | < 2.4.7-1ubuntu4.22+esm5 | UNKNOWN |
ubuntu | 16.04 | noarch | apache2 | < 2.4.18-2ubuntu3.17+esm6 | UNKNOWN |
httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-26377
launchpad.net/bugs/cve/CVE-2022-26377
nvd.nist.gov/vuln/detail/CVE-2022-26377
security-tracker.debian.org/tracker/CVE-2022-26377
ubuntu.com/security/notices/USN-5487-1
ubuntu.com/security/notices/USN-5487-2
ubuntu.com/security/notices/USN-5487-3
www.cve.org/CVERecord?id=CVE-2022-26377
www.openwall.com/lists/oss-security/2022/06/08/2
5 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
7.5 High
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
0.006 Low
EPSS
Percentile
79.3%