VDB
BDU%3A2022-05209
BDU%3A2022-05209
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Уязвимость модуля mod_wsgi веб-сервера Apache, связанная с ошибками при обработке заголовока X-Client-IP, позволяющая нарушителю получить несанкционированный доступ к сетевым службам
Risk Scores
CVSS 2.0
5.099999904632568
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Canonical Ltd., Novell Inc., Red Hat Inc., Сообщество свободного программного обеспечения, ООО «Ред Софт», ООО «РусБИТех-Астра», АО «ИВК», АО "НППКТ", АО «НТЦ ИТ РОСА» | Ubuntu, SUSE Linux Enterprise Server for SAP Applications, Suse Linux Enterprise Server, SUSE Linux Enterprise High Performance Computing, SUSE Linux Enterprise Module for Web Scripting, Red Hat Enterprise Linux, SUSE Linux Enterprise Module for Public Cloud, SUSE OpenStack Cloud, Debian GNU/Linux, SUSE Enterprise Storage, HPE Helion Openstack, Red Hat Software Collections, SUSE CaaS Platform, SUSE Manager Proxy, SUSE Manager Retail Branch Server, SUSE Manager Server, SUSE Linux Enterprise Module for Server Applications, РЕД ОС (запись в едином реестре российских программ №3751), Astra Linux Special Edition (запись в едином реестре российских программ №369), Альт 8 СП (запись в едином реестре российских программ №4305), SUSE Business Critical Linux, mod_wsgi, ОСОН ОСнова Оnyx (запись в едином реестре российских программ №5913), ROSA Virtualization (запись в едином реестре российских программ №5091), АЛЬТ СП 10 |
Timeline
- Aug 22, 2022 CVE Published
- Sep 13, 2024 CVE Updated
- Mar 19, 2026 Distribution Patch
References
- https://gihub.com/GrahamDumpleton/mod_wsgi/commit/af3c0c2736bc0b0b01fa0f0aad3c904b7fa9c751 url
- https://www.suse.com/security/cve/CVE-2022-2255.html url
- https://ubuntu.com/security/notices/USN-5551-1 url
- https://поддержка.нппкт.рф/bin/view/ОСнова/Обновления/2.6/ url
- https://wiki.astralinux.ru/astra-linux-se17-bulletin-2022-1110SE17 url
- https://wiki.astralinux.ru/astra-linux-se47-bulletin-2022-1121SE47 url
- https://altsp.su/obnovleniya-bezopasnosti/ url
- https://github.com/GrahamDumpleton/mod_wsgi/blob/4.9.2/src/server/mod_wsgi.c#L13940-L13941 url
- https://security-tracker.debian.org/tracker/CVE-2022-2255 advisory
- https://access.redhat.com/security/cve/cve-2022-2255 advisory
- https://abf.rosalinux.ru/advisories/ROSA-SA-2024-2363 advisory
- http://repo.red-soft.ru/redos/7.3c/x86_64/updates/ advisory