CVE-2022-28330
Published on: Not Yet Published
Last Modified on: 06/24/2022 04:15:00 PM UTC
Certain versions of Http Server from Apache contain the following vulnerability:
Apache HTTP Server 2.4.53 and earlier on Windows may read beyond bounds when configured to process requests with the mod_isapi module.
- CVE-2022-28330 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache HTTP Server version <= 2.4.53
CVSS3 Score: 5.3 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | httpd.apache.org text/html |
![]() |
oss-security - CVE-2022-28330: Apache HTTP Server: read beyond bounds in mod_isapi | www.openwall.com text/html |
![]() |
June 2022 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 150539 Apache HTTP Server 2.4.53 Multiple Vulnerabilities
- 240996 Red Hat Update for JBoss Core Services (RHSA-2022:8840)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 353971 Amazon Linux Security Advisory for httpd24 : ALAS-2022-1607
- 353988 Amazon Linux Security Advisory for httpd : ALAS2-2022-1812
- 354482 Amazon Linux Security Advisory for httpd : ALAS2022-2022-202
- 354513 Amazon Linux Security Advisory for httpd : ALAS2022-2022-110
- 354577 Amazon Linux Security Advisory for httpd : ALAS2022-2022-202
- 355264 Amazon Linux Security Advisory for httpd : ALAS2023-2023-072
- 501353 Alpine Linux Security Update for apache2
- 672082 EulerOS Security Update for httpd (EulerOS-SA-2022-2320)
- 672128 EulerOS Security Update for httpd (EulerOS-SA-2022-2291)
- 672254 EulerOS Security Update for httpd (EulerOS-SA-2022-2685)
- 672282 EulerOS Security Update for httpd (EulerOS-SA-2022-2653)
- 690877 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (49adfbe5-e7d1-11ec-8fbd-d4c9ef517024)
- 730739 IBM Aspera Faspex Multiple Security Vulnerabilities (6952319)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Http Server | All | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
Discovery Credit
The Apache HTTP Server project would like to thank Ronald Crane (Zippenhop LLC) for reporting this issue
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
Apache HTTP Serverの脆弱性情報(Moderate: CVE-2022-26377, Low: CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-29… twitter.com/i/web/status/1… | 2022-06-08 14:24:18 |
![]() |
Apache HTTP Serverの脆弱性(Moderate: CVE-2022-26377, Low: CVE-2022-28330, CVE-2022-28614, CVE-2022-28615, CVE-2022-2940… twitter.com/i/web/status/1… | 2022-06-08 18:37:00 |
![]() |
CVE-2022-28330 : #Apache HTTP Server 2.4.53 and earlier on #Windows may read beyond bounds when configured to proce… twitter.com/i/web/status/1… | 2022-06-09 16:33:50 |
![]() |
CVE-2022-28330 | 2022-06-09 16:39:55 |