peter bassill · operator
$ cve CVE-2022-23943 JSON

CVE-2022-23943

9.8
CRITICAL · CVSS 3.1 · EPSS 50.4% (pctl 99)

Patch early

EPSS 50.4% — above the 10% action threshold.

Description

Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior versions.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS50.4% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2022-03-14
Last modified2026-06-17

Affected (5)

VendorProduct
apachehttp server
debiandebian linux
fedoraprojectfedora
oraclehttp server
oraclezfs storage appliance kit

References

→ the Explorer  ·  watch your stack  ·  NVD