Apache – CVE-2022-22720

Description

Cytrix has detected that the Version of Apache HTTP Server being used is vulnerable to Inconsistent Interpretation of HTTP Requests, also known as ‘HTTP Request/Response Smuggling’ (CWE-444). This vulnerability is catalogued as CVE-2022-22720.

The version of Apache HTTP Server being used fails to close inbound connection when errors are encountered discarding the request body.
That will expose the server to HTTP Request Smuggling.

There’s a chance that this vulnerability will allow attackers to modify system files and information.

Recommendation

To fix CVE-2022-22720, upgrade the version of Apache HTTP Server being used to 2.4.53 or higher.

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22720

https://cwe.mitre.org/data/definitions/444.html

< Return to all Vulnerabilities

Using VPN

What is a VPN? Why should someone be using VPN? Which Problems does is solve? and what is the advantages and disadvantages of it? Let’s

Read More »

Servers 101

Let’s have a “quick” Servers 101 Course. Courtesy of Cytrix! If you’ve been on the internet for over an hour, you probably already heard of

Read More »