apache http-server CVE-2022-30522 vulnerability in Apache and Other Products
Published on June 9, 2022

mod_sed denial of service

product logo product logo product logo product logo
If Apache HTTP Server 2.4.53 is configured to do transformations with mod_sed in contexts where the input to mod_sed may be very large, mod_sed may make excessively large memory allocations and trigger an abort.

Vendor Advisory Vendor Advisory Vendor Advisory NVD

Timeline

released in 2.4.54

Weakness Type

What is a Stack Exhaustion Vulnerability?

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

CVE-2022-30522 has been classified to as a Stack Exhaustion vulnerability or weakness.


Products Associated with CVE-2022-30522

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2022-30522 are published in these products:

 
 
 
 

Affected Versions

Apache Software Foundation Apache HTTP Server Version 2.4.53 is affected by CVE-2022-30522

Exploit Probability

EPSS
11.59%
Percentile
93.50%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.