9.8
CVSSv3

CVE-2022-31813

Published: 09/06/2022 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Apache HTTP Server 2.4.53 and previous versions may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism. This may be used to bypass IP based authentication on the origin server/application.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server

netapp clustered data ontap -

fedoraproject fedora 35

fedoraproject fedora 36

Vendor Advisories

Debian Bug report logs - #1012513 apache2: CVE-2022-31813 CVE-2022-26377 CVE-2022-28614 CVE-2022-28615 CVE-2022-29404 CVE-2022-30522 CVE-2022-30556 Package: src:apache2; Maintainer for src:apache2 is Debian Apache Maintainers <debian-apache@listsdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, ...
Several security issues were fixed in Apache HTTP Server ...
USN-5487-1 introduced a regression in Apache ...
USN-5487-1 introduced a regression in Apache HTTP Server ...
Synopsis Moderate: httpd:24 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for the httpd:24 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update ...
Synopsis Moderate: httpd security, bug fix, and enhancement update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for httpd is now available for Red Hat Enterprise Linux 9Red Hat Product Security has rated this ...
Synopsis Moderate: httpd24-httpd security and bug fix update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update for httpd24-httpd is now available for Red Hat Software CollectionsRed Hat Product Security has rated ...
Synopsis Moderate: Red Hat JBoss Core Services Apache HTTP Server 2451 SP1 security update Type/Severity Security Advisory: Moderate Red Hat Insights patch analysis Identify and remediate systems affected by this advisory View affected systems Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Securi ...
Synopsis Important: Red Hat JBoss Core Services Apache HTTP Server 2451 SP1 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Core ServicesRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base sco ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...
Apache HTTP Server 2453 and earlier may not send the X-Forwarded-* headers to the origin server based on client side Connection header hop-by-hop mechanism This may be used to bypass IP based authentication on the origin server/application ...
A vulnerability (CVE-2022-31813) exists in Cosminexus HTTP Server and Hitachi Web Server Affected products and versions are listed below Please upgrade your version to the appropriate version ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...
An HTTP request smuggling vulnerability was found in the mod_proxy_ajp module of httpd This flaw allows an attacker to smuggle requests to the AJP server, where it forwards requests (CVE-2022-26377) An out-of-bounds read vulnerability was found in the mod_isapi module of httpd The issue occurs when httpd is configured to process requests with th ...

ICS Advisories