oss-sec mailing list archives
CVE-2022-26377: Apache HTTP Server: mod_proxy_ajp: Possible request smuggling
From: Stefan Eissing <icing () apache org>
Date: Wed, 08 Jun 2022 09:42:22 +0000
Severity: moderate
Description:
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP
Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache
HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
Credit:
Ricter Z @ 360 Noah Lab
References:
https://httpd.apache.org/security/vulnerabilities_24.html
Current thread:
- CVE-2022-26377: Apache HTTP Server: mod_proxy_ajp: Possible request smuggling Stefan Eissing (Jun 08)
