CVE-2022-30522
Published on: Not Yet Published
Last Modified on: 09/07/2022 05:35:00 PM UTC
Certain versions of Http Server from Apache contain the following vulnerability:
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.
- CVE-2022-30522 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Apache Software Foundation - Apache HTTP Server version = 2.4.53
CVSS3 Score: 7.5 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 5 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | LOW | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Apache HTTPD: Multiple Vulnerabilities (GLSA 202208-20) — Gentoo security | security.gentoo.org text/html |
![]() |
[SECURITY] Fedora 36 Update: httpd-2.4.54-3.fc36 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | httpd.apache.org text/html |
![]() |
oss-security - CVE-2022-30522: Apache HTTP Server: mod_sed denial of service | www.openwall.com text/html |
![]() |
[SECURITY] Fedora 35 Update: httpd-2.4.54-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org text/html |
![]() |
June 2022 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 150539 Apache HTTP Server 2.4.53 Multiple Vulnerabilities
- 160250 Oracle Enterprise Linux Security Update for httpd:2.4 (ELSA-2022-7647)
- 160309 Oracle Enterprise Linux Security Update for httpd (ELSA-2022-8067)
- 180881 Debian Security Update for apache2 (CVE-2022-30522)
- 198838 Ubuntu Security Notification for Apache Hypertext Transfer Protocol (HTTP) Server Vulnerabilities (USN-5487-1)
- 240698 Red Hat Update for httpd24-httpd (RHSA-2022:6753)
- 240854 Red Hat Update for httpd:2.4 (RHSA-2022:7647)
- 240885 Red Hat Update for httpd security (RHSA-2022:8067)
- 240996 Red Hat Update for JBoss Core Services (RHSA-2022:8840)
- 282882 Fedora Security Update for httpd (FEDORA-2022-e620fb15d5)
- 282903 Fedora Security Update for httpd (FEDORA-2022-b54a8dee29)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 353971 Amazon Linux Security Advisory for httpd24 : ALAS-2022-1607
- 353988 Amazon Linux Security Advisory for httpd : ALAS2-2022-1812
- 354482 Amazon Linux Security Advisory for httpd : ALAS2022-2022-202
- 354513 Amazon Linux Security Advisory for httpd : ALAS2022-2022-110
- 354577 Amazon Linux Security Advisory for httpd : ALAS2022-2022-202
- 355264 Amazon Linux Security Advisory for httpd : ALAS2023-2023-072
- 501353 Alpine Linux Security Update for apache2
- 672022 EulerOS Security Update for httpd (EulerOS-SA-2022-2256)
- 672041 EulerOS Security Update for httpd (EulerOS-SA-2022-2270)
- 672052 EulerOS Security Update for httpd (EulerOS-SA-2022-2222)
- 672060 EulerOS Security Update for httpd (EulerOS-SA-2022-2243)
- 672082 EulerOS Security Update for httpd (EulerOS-SA-2022-2320)
- 672128 EulerOS Security Update for httpd (EulerOS-SA-2022-2291)
- 672228 EulerOS Security Update for httpd (EulerOS-SA-2022-2614)
- 690877 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (49adfbe5-e7d1-11ec-8fbd-d4c9ef517024)
- 710595 Gentoo Linux Apache HTTPD Multiple Vulnerabilities (GLSA 202208-20)
- 730739 IBM Aspera Faspex Multiple Security Vulnerabilities (6952319)
- 752247 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:2101-1)
- 752248 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:2099-1)
- 752307 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:2302-1)
- 752326 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:2338-1)
- 752331 SUSE Enterprise Linux Security Update for apache2 (SUSE-SU-2022:2342-1)
- 940741 AlmaLinux Security Update for httpd:2.4 (ALSA-2022:7647)
- 940823 AlmaLinux Security Update for httpd (ALSA-2022:8067)
- 960175 Rocky Linux Security Update for httpd:2.4 (RLSA-2022:7647)
- 960481 Rocky Linux Security Update for httpd (RLSA-2022:8067)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Apache | Http Server | 2.4.53 | All | All | All |
Application | Apache | Http Server | All | All | All | All |
Operating System | Fedoraproject | Fedora | 35 | All | All | All |
Operating System | Fedoraproject | Fedora | 36 | All | All | All |
Application | Netapp | Clustered Data Ontap | - | All | All | All |
- cpe:2.3:a:apache:http_server:2.4.53:*:*:*:*:*:*:*:
- cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*:
- cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:clustered_data_ontap:-:*:*:*:*:*:*:*:
Discovery Credit
This issue was found by Brian Moussalli from the JFrog Security Research team
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
[email protected] modified www/apache-httpd: security update to 2.4.54 fixes CVE-2022-31813, CVE-2022-30556, CVE-2022-30522… twitter.com/i/web/status/1… | 2022-06-09 07:55:18 |
![]() |
CVE-2022-30522 : If #Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where t… twitter.com/i/web/status/1… | 2022-06-09 16:35:32 |
![]() |
CVE-2022-30522 | 2022-06-09 16:39:57 |
![]() |
CVE-2022-30522 - Apache httpd "mod_sed" DoS vulnerability | 2022-06-28 17:27:20 |