CVE-2022-38333
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
19/09/2022
Last modified:
07/11/2023
Description
Openwrt before v21.02.3 and Openwrt v22.03.0-rc6 were discovered to contain two skip loops in the function header_value(). This vulnerability allows attackers to access sensitive information via a crafted HTTP request.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:openwrt:openwrt:*:*:*:*:*:*:*:* | 21.02.3 (excluding) | |
| cpe:2.3:o:openwrt:openwrt:22.03.0:rc6:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://git.openwrt.org/?p=project/cgi-io.git%3Ba%3Dcommit%3Bh%3D901b0f0463c9d16a8cf5b9ed37118d8484bc9176
- https://git.openwrt.org/?p=project/cgi-io.git%3Ba%3Dcommitdiff%3Bh%3D901b0f0463c9d16a8cf5b9ed37118d8484bc9176
- https://git.openwrt.org/?p=project/cgi-io.git%3Ba%3Dpatch%3Bh%3D901b0f0463c9d16a8cf5b9ed37118d8484bc9176



