Apache – CVE-2022-28615

Description

Cytrix has detected that the version of Apache HTTP Server being used is vulnerable to Information Disclosure and denial of service (DoS).
also known as CVE-2022-28615.

An attacker could abuse the fact that a read beyond bounds in ap_strcmp_match() by providing an extremely large input buffer.
While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may potentially be affected.

This will cause a decrease in performance and also for interruptions in the availability of resources.

Severity/Score

CVSS Version 3.x – 9.1 Critical

Recommendation

To fix CVE-2022-28615, upgrade the version of Apache Server being used to 2.4.54.

References

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-28615

https://cwe.mitre.org/data/definitions/190.html

< Return to all Vulnerabilities

Red Team

You’ve probably heard that there are teams in the Cyber field called Red Team and Blue Team. Let’s talk about the red one, shall we?

Read More »

The Dark Web

Let’s talk about the darker and more mysterious side of the internet, also known as The Dark Web. You’ve probably heard about it, whether it’s

Read More »

Passwords 101

Unlike basketballs, “passwords” are things we don’t want to be passed around, especially in a society built around the idea that “mystery” is appealing. We

Read More »