Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.54 and prior versions. References: https://httpd.apache.org/security/vulnerabilities_24.html https://www.openwall.com/lists/oss-security/2023/01/17/6
Created httpd tracking bugs for this issue: Affects: fedora-all [bug 2162100]
Upstream fix is: https://svn.apache.org/viewvc?view=revision&revision=1906540
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2023:0852 https://access.redhat.com/errata/RHSA-2023:0852
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2023:0970 https://access.redhat.com/errata/RHSA-2023:0970
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2022-36760
This issue has been addressed in the following products: Red Hat JBoss Core Services Via RHSA-2023:4628 https://access.redhat.com/errata/RHSA-2023:4628
This issue has been addressed in the following products: JBoss Core Services on RHEL 7 JBoss Core Services for RHEL 8 Via RHSA-2023:4629 https://access.redhat.com/errata/RHSA-2023:4629