Description
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3384-1 | tomcat9 security update |
Debian DSA |
DSA-5381-1 | tomcat9 security update |
EUVD |
EUVD-2022-7390 | If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a reverse proxy that also failed to reject the request with the invalid header. |
Github GHSA |
GHSA-p22x-g9px-3945 | Apache Tomcat may reject request containing invalid Content-Length header |
Ubuntu USN |
USN-6880-1 | Tomcat vulnerability |
References
History
Tue, 06 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2025-05-06T15:09:20.374Z
Reserved: 2022-10-03T00:00:00.000Z
Link: CVE-2022-42252
Updated: 2024-08-03T13:03:45.683Z
Status : Modified
Published: 2022-11-01T09:15:10.817
Modified: 2025-05-06T16:15:26.137
Link: CVE-2022-42252
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN