Back to bug 2161777

Who When What Removed Added
Guilherme de Almeida Suckevicz 2023-01-18 17:51:44 UTC Summary CVE-2022-36760 Apache HTTP Server: mod_proxy_ajp Possible request smuggling CVE-2022-36760 httpd: mod_proxy_ajp: possible request smuggling
Guilherme de Almeida Suckevicz 2023-01-18 18:01:08 UTC Fixed In Version Apache HTTP Server 2.4.55 httpd 2.4.55
Guilherme de Almeida Suckevicz 2023-01-18 18:53:34 UTC CC asoldano, bbaranow, bmaxwell, brian.stansberry, cdewolf, chazlett, csutherl, darran.lofthouse, dkreling, dosoudil, fjuma, hhorak, ivassile, iweiss, jclere, jorton, jwon, lgao, luhliari, mosmerov, msochure, msvehla, mturk, nwallace, peholase, pjindal, plodge, pmackay, rstancel, smaestri, szappis, tom.jenkinson
Guilherme de Almeida Suckevicz 2023-01-18 19:02:30 UTC Depends On 2162100
Guilherme de Almeida Suckevicz 2023-01-18 19:08:27 UTC Comment 0 updated
Guilherme de Almeida Suckevicz 2023-01-18 19:27:18 UTC Summary CVE-2022-36760 httpd: mod_proxy_ajp: possible request smuggling CVE-2022-36760 httpd: mod_proxy_ajp: Possible request smuggling
Guilherme de Almeida Suckevicz 2023-01-18 19:40:42 UTC CC jburrell
Guilherme de Almeida Suckevicz 2023-01-19 18:32:20 UTC Depends On 2162509, 2162510, 2162511
Yasuhiro Ozone 2023-01-19 22:20:29 UTC CC gsuckevi, yozone
Flags needinfo?(gsuckevi)
Guilherme de Almeida Suckevicz 2023-01-20 14:55:27 UTC Flags needinfo?(gsuckevi)
Doc Text A flaw was found in the mod_proxy_ajp module of httpd. The connection is not closed when there is an invalid Transfer-Encoding header, allowing an attacker to smuggle requests to the AJP server, where it forwards requests.
RHEL Program Management Team 2023-01-31 15:50:19 UTC CC icesalov
Flags needinfo?(zmiele)
Depends On 2165974
RHEL Program Management Team 2023-01-31 15:52:25 UTC Depends On 2165978
Guilherme de Almeida Suckevicz 2023-01-31 17:36:21 UTC CC bdettelb, caswilli, jkoehler, kaycoth, micjohns, sthirugn
Guilherme de Almeida Suckevicz 2023-02-01 18:42:24 UTC Flags needinfo?(zmiele)
errata-xmlrpc 2023-02-21 09:32:11 UTC Link ID Red Hat Product Errata RHSA-2023:0852
errata-xmlrpc 2023-02-28 08:21:00 UTC Link ID Red Hat Product Errata RHSA-2023:0970
Product Security DevOps Team 2023-02-28 12:44:26 UTC Resolution --- ERRATA
Status NEW CLOSED
Last Closed 2023-02-28 12:44:26 UTC
errata-xmlrpc 2023-08-15 17:37:14 UTC Link ID Red Hat Product Errata RHSA-2023:4628
errata-xmlrpc 2023-08-15 17:40:48 UTC Link ID Red Hat Product Errata RHSA-2023:4629

Back to bug 2161777