Description
Cytrix has detected that the Version of Apache HTTP Server being used is vulnerable to Inconsistent Interpretation of HTTP Requests (‘HTTP Request Smuggling’).
Also known as CVE-2022-26377.
Abusing this vulnerability in mod_proxy_ajp of Apache HTTP Server allow attackers to smuggle requests to the AJP server it forwards requests to.
There’s a chance that this vulnerability will allow attackers to modify system files and information.
Recommendation
To fix CVE-2022-26377, upgrade the version of Apache HTTP Server being used to 2.4.54 or higher.
References
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-26377