CVE-2022-28615

Read beyond bounds in ap_strcmp_match()

Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.


We have discovered 1,834,229 live websites that are affected by CVE-2022-28615.

Test my site




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains1,834,229 live websites (58.14% of Apache install base)
Vulnerable Versions
  • from 0 before 2.4.53
Vulnerable Versions Count134 versions ( 91.16% of all versions)


Common Weakness Enumeration

CWE-190 Integer Overflow or Wraparound



Details

  • Published - Jun 8, 2022
  • Updated - Aug 3, 2024

Credits

  • The Apache HTTP Server project would like to thank Ronald Crane (Zippenhop LLC) for reporting this issue

CVE-2022-28615 usage by Country

United States575,033 websites



Germany209,422 websites
Taiwan112,356 websites
France105,328 websites
Japan76,822 websites
Russia68,551 websites
Netherlands58,614 websites
Singapore50,244 websites
Czech Republic46,232 websites
Italy42,349 websites

CVE-2022-28615 usage by TLD

.com720,286 websites
.de131,002 websites
.org81,167 websites
.net74,674 websites
.ru59,938 websites
.nl43,732 websites
.it41,648 websites
.cz38,510 websites
.fr31,216 websites
.jp30,946 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-28615

Top websites that are affected by CVE-2022-28615. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*****.***********.com Canada***
*********.com United States***
*********.*************.se United States***
***********.org United States***
*********.net United States***
********.*********.com Singapore*,***
***.****.us United States*,***
***.*********.com Singapore*,***
See full domain list

FAQ

CVE-2022-28615 is Integer Overflow or Wraparound in Apache
A total of 1,834,229 websites have been identified as vulnerable to CVE-2022-28615, discovered through global website indexing conducted by WebTechSurvey.
Apache is susceptible to CVE-2022-28615 vulnerability.
Apache versions before 2.4.53 are vulnerable to CVE-2022-28615.
Version 2.4.53 of Apache addresses the CVE-2022-28615 security vulnerability.