oss-sec mailing list archives
CVE-2022-26377: Apache HTTP Server: mod_proxy_ajp: Possible request smuggling
From: Stefan Eissing <icing () apache org>
Date: Wed, 08 Jun 2022 09:42:22 +0000
Severity: moderate Description: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions. Credit: Ricter Z @ 360 Noah Lab References: https://httpd.apache.org/security/vulnerabilities_24.html
Current thread:
- CVE-2022-26377: Apache HTTP Server: mod_proxy_ajp: Possible request smuggling Stefan Eissing (Jun 08)