Apache HTTP Server: mod_proxy_ajp Possible request smuggling
Published Jan 17, 2023
9.0
CRITICALCVSS 3.1
EPSS 1.88%
Description
Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions.
Affected products
-
- Version 2.4StatusaffectedConstraints<=2.4.54
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache HTTP Server | unaffected |
|
- ≥ 2.4.0 · < 2.4.55
No data.
JBoss Core Services for RHEL 8
jbcs-httpd24-httpd-0:2.4.57-5.el8jbcs
Fixed · RHSA-2023:4629
JBoss Core Services on RHEL 7
jbcs-httpd24-httpd-0:2.4.57-5.el7jbcs
Fixed · RHSA-2023:4629
Red Hat Enterprise Linux 8
httpd:2.4-8070020230131172653.bd1311ed
Fixed · RHSA-2023:0852
Red Hat Enterprise Linux 9
httpd-0:2.4.53-7.el9_1.1
Fixed · RHSA-2023:0970
Red Hat Enterprise Linux 6
httpd
Out of support scope
Red Hat Enterprise Linux 7
httpd
Out of support scope
Red Hat JBoss Enterprise Application Platform 6
httpd22
Out of support scope
Red Hat Software Collections
httpd24-httpd
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| JBoss Core Services for RHEL 8 | jbcs-httpd24-httpd-0:2.4.57-5.el8jbcs | Fixed | RHSA-2023:4629 |
| JBoss Core Services on RHEL 7 | jbcs-httpd24-httpd-0:2.4.57-5.el7jbcs | Fixed | RHSA-2023:4629 |
| Red Hat Enterprise Linux 8 | httpd:2.4-8070020230131172653.bd1311ed | Fixed | RHSA-2023:0852 |
| Red Hat Enterprise Linux 9 | httpd-0:2.4.53-7.el9_1.1 | Fixed | RHSA-2023:0970 |
| Red Hat Enterprise Linux 6 | httpd | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | httpd | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 6 | httpd22 | Out of support scope | n/a |
| Red Hat Software Collections | httpd24-httpd | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This flaw only affects configurations with mod_proxy_ajp loaded and with an AJP backend configured. If there is no proxy configured to an AJP backend the server is not affected and no further mitigation is needed. For more information about the mitigation, check the mitigation section below. The httpd mod_proxy_ajp module is enabled by default on Red Hat Enterprise Linux 6, 7, 8, 9, and in RHSCL. However, there are no directives forwarding requests using the AJP protocol. This flaw has been rated as having a security impact of moderate, and is not currently planned to be addressed in future updates of Red Hat Enterprise Linux 7. Red Hat Enterprise Linux 7 is now in Maintenance Support 2 Phase of the support and maintenance life cycle. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata.
References (7)
- https://access.redhat.com/security/cve/CVE-2022-36760 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2161777 Issue Tracking
- https://httpd.apache.org/security/vulnerabilities_24.html vendor-advisoryMailing ListVendor Advisory
- https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-36760
- https://nvd.nist.gov/vuln/detail/CVE-2022-36760
- https://security.gentoo.org/glsa/202309-01
- https://www.cve.org/CVERecord?id=CVE-2022-36760
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-36760 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2161777 | Issue Tracking | |
| https://httpd.apache.org/security/vulnerabilities_24.html | vendor-advisoryMailing ListVendor Advisory | |
| https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2022-36760 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-36760 | ||
| https://security.gentoo.org/glsa/202309-01 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-36760 |
Change history (0)
No recorded changes yet.