Related Vulnerabilities: CVE-2022-22720  

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Description

The MITRE CVE dictionary describes this issue as:

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Additional Information

  • Bugzilla 2064321: CVE-2022-22720 httpd: HTTP request smuggling vulnerability in Apache HTTP Server 2.4.52 and earlier
  • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
  • FAQ: Frequently asked questions about CVE-2022-22720