Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
We have discovered 1,834,229 live websites that are affected by CVE-2022-28615.
Product | |
Category | Web Servers |
Vulnerable Domains | 1,834,229 live websites (58.14% of Apache install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 134 versions ( 91.16% of all versions) |
![]() | 575,033 websites |
![]() | 209,422 websites |
![]() | 112,356 websites |
![]() | 105,328 websites |
![]() | 76,822 websites |
![]() | 68,551 websites |
![]() | 58,614 websites |
![]() | 50,244 websites |
![]() | 46,232 websites |
![]() | 42,349 websites |
.com | 720,286 websites |
.de | 131,002 websites |
.org | 81,167 websites |
.net | 74,674 websites |
.ru | 59,938 websites |
.nl | 43,732 websites |
.it | 41,648 websites |
.cz | 38,510 websites |
.fr | 31,216 websites |
.jp | 30,946 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*******.com | ![]() | *** | |
*************.***.****.****.************.net | ![]() | *** | |
*****.***********.com | ![]() | *** | |
*********.com | ![]() | *** | |
*********.*************.se | ![]() | *** | |
***********.org | ![]() | *** | |
*********.net | ![]() | *** | |
********.*********.com | ![]() | *,*** | |
***.****.us | ![]() | *,*** | |
***.*********.com | ![]() | *,*** |
FAQ