CVE-2022-22719: mod_lua Use of uninitialized value of in r:parsebody
A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier.
Credit
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-22719.
What is the severity of CVE-2022-22719?
The severity of CVE-2022-22719 is high.
What is the affected software?
The affected software includes Apple macOS Monterey 12.4, Apple Catalina, Apple macOS Big Sur 11.6.6, Red Hat httpd 2.4.53, and Apache Tomcat 0:2.4.53-7.el9.
How can I fix this vulnerability?
To fix this vulnerability, update to Apache version 2.4.53 or apply the appropriate patches provided by your software vendor.
Are there any references for further information?
Yes, you can refer to the following URLs for further information: [URL1](https://support.apple.com/en-us/HT213257), [URL2](https://support.apple.com/en-us/HT213255), [URL3](https://support.apple.com/en-us/HT213256).