VulnerabilityModified
CVE-2022-37436
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body.
MEDIUM 5.3EPSS 61.0%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 61.0%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Prior to Apache HTTP Server 2.4.55, a malicious backend can cause the response headers to be truncated early, resulting in some headers being incorporated into the response body. If the later headers have any security purpose, they will not be interpreted by the client.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 60.99% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-113, CWE-436
- Affected
- apache/http server
- Source
- security@apache.org
References
- https://httpd.apache.org/security/vulnerabilities_24.htmlRelease Notes, Vendor Advisory
- https://security.gentoo.org/glsa/202309-01
- https://httpd.apache.org/security/vulnerabilities_24.htmlRelease Notes, Vendor Advisory
- https://security.gentoo.org/glsa/202309-01
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.