← back
CVE-2022-30556CWE-200

Information Disclosure in mod_lua with websockets

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 4.7%
exploitation probability
4.7%top 9% of all CVEs
observed exploitation
nono source reports it
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.