CVE-2022-42252
Summary
| CVE | CVE-2022-42252 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-11-01 09:15:00 UTC |
| Updated | 2023-05-30 06:15:00 UTC |
| Description | If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header. |
Risk And Classification
Problem Types: CWE-444
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread/zzcxzvqfdqn515zfs3dxb7n8gty589sq | MISC | lists.apache.org | |
| Apache Tomcat: Multiple Vulnerabilities (GLSA 202305-37) — Gentoo security | MISC | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 150590 Apache Tomcat HTTP Request Smuggling Vulnerability (CVE-2022-42252)
- 181696 Debian Security Update for tomcat9 (DLA 3384-1)
- 181700 Debian Security Update for tomcat9 (DSA 5381-1)
- 184006 Debian Security Update for tomcat9 (CVE-2022-42252)
- 296098 Oracle Solaris 11.4 Support Repository Update (SRU) 52.132.2 Missing (CPUOCT2022)
- 355221 Amazon Linux Security Advisory for tomcat9 : ALAS2023-2023-140
- 356166 Amazon Linux Security Advisory for tomcat : ALASTOMCAT9-2023-005
- 356210 Amazon Linux Security Advisory for tomcat : ALASTOMCAT8.5-2023-002
- 356279 Amazon Linux Security Advisory for tomcat : ALASTOMCAT9-2023-002
- 378055 Dell NetWorker Security Update for an Apache Tomcat Vulnerability (DSA-2023-040)
- 672612 EulerOS Security Update for tomcat (EulerOS-SA-2023-1341)
- 690992 Free Berkeley Software Distribution (FreeBSD) Security Update for tomcat (556fdf03-6785-11ed-953b-002b67dfc673)
- 710733 Gentoo Linux Apache Tomcat Multiple Vulnerabilities (GLSA 202305-37)
- 730644 Apache Tomcat request smuggling Vulnerability (CVE-2022-42252)
- 730648 Apache Tomcat request smuggling Vulnerability (CVE-2022-42252)
- 730657 Apache Tomcat request smuggling Vulnerability (CVE-2022-42252)
- 730663 Apache Tomcat request smuggling Vulnerability (CVE-2022-42252)
- 730982 Atlassian Confluence Data Center and Server Request Smuggling Vulnerability (CONFSERVER-93168)
- 752834 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:4221-1)
- 752849 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:4257-1)
- 752970 SUSE Enterprise Linux Security Update for tomcat (SUSE-SU-2022:4303-1)