ZeroHour

CVE-2022-22720

CVSS 3.1
9.8 critical
EPSS
28%p98
Published
()
Modified
Description

Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling

Vendors
apachefedoraprojectdebianoracleapple
Products
http server, fedora, debian linux, enterprise manager ops center, zfs storage appliance kit, mac os x, macos
Weakness
CWE-444
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news