We found results for “”
CVE-2022-42252
Good to know:
Date: October 31, 2022
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
Language: Java
Severity Score
Related Resources (14)
Severity Score
Weakness Type (CWE)
Top Fix
Upgrade Version
Upgrade to version org.apache.tomcat.embed:tomcat-embed-core:10.1.1;org.apache.tomcat.embed:tomcat-embed-core:10.0.27;org.apache.tomcat.embed:tomcat-embed-core:8.5.83;org.apache.tomcat.embed:tomcat-embed-core:9.0.68;org.apache.tomcat:tomcat-coyote:10.1.1;org.apache.tomcat:tomcat-coyote:10.0.27;org.apache.tomcat:tomcat-coyote:9.0.68
CVSS v3.1
| Base Score: |
|
|---|---|
| Attack Vector (AV): | NETWORK |
| Attack Complexity (AC): | LOW |
| Privileges Required (PR): | NONE |
| User Interaction (UI): | NONE |
| Scope (S): | UNCHANGED |
| Confidentiality (C): | NONE |
| Integrity (I): | HIGH |
| Availability (A): | NONE |
Vulnerabilities
Projects
Contact Us


