ืžื”ื“ื•ืจืช ืฉืจืช http ืฉืœ Apache 2.4.54 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ืคื•ืจืกื ืžื”ื“ื•ืจืช ืฉืจืช HTTP ืฉืœ Apache 2.4.53, ื”ืžืฆื™ื’ื” 19 ืฉื™ื ื•ื™ื™ื ื•ืžืชืงืŸ 8 ืคื’ื™ืขื•ื™ื•ืช:

  • CVE-2022-31813 ื”ื™ื ืคื’ื™ืขื•ืช ื‘-mod_proxy ืฉื™ื›ื•ืœื” ืœื—ืกื•ื ืืช ืฉืœื™ื—ืช ื›ื•ืชืจื•ืช X-Forwarded-* ืขื ืžื™ื“ืข ืขืœ ื›ืชื•ื‘ืช ื”-IP ืžืžื ื” ื”ื’ื™ืขื” ื”ื‘ืงืฉื” ื”ืžืงื•ืจื™ืช. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื‘ืขื™ื” ื›ื“ื™ ืœืขืงื•ืฃ ื”ื’ื‘ืœื•ืช ื’ื™ืฉื” ืขืœ ืกืžืš ื›ืชื•ื‘ื•ืช IP.
  • CVE-2022-30556 ื”ื™ื ืคื’ื™ืขื•ืช ื‘-mod_lua ื”ืžืืคืฉืจืช ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืžื—ื•ืฅ ืœืžืื’ืจ ื”ืžื•ืงืฆื” ื‘ืืžืฆืขื•ืช ืžื ื™ืคื•ืœืฆื™ื•ืช ืขื ื”ืคื•ื ืงืฆื™ื” r:wsread() ื‘ืกืงืจื™ืคื˜ื™ื ืฉืœ Lua.
  • CVE-2022-30522 - ืžื ื™ืขืช ืฉื™ืจื•ืช (ืžื—ื•ืฅ ืœื–ื™ื›ืจื•ืŸ ื–ืžื™ืŸ) ืชื•ืš ืขื™ื‘ื•ื“ ื ืชื•ื ื™ื ืžืกื•ื™ืžื™ื ืขืœ ื™ื“ื™ mod_sed.
  • CVE-2022-29404 - ืžื ื™ืขืช ืฉื™ืจื•ืช mod_lua ืžื ื•ืฆืœ ืขืœ ื™ื“ื™ ืฉืœื™ื—ืช ื‘ืงืฉื•ืช ื‘ืขืœื•ืช ืžื‘ื ื” ืžื™ื•ื—ื“ ืœืžื˜ืคืœื™ Lua ื‘ืืžืฆืขื•ืช ื”ืงืจื™ืื” r:parsebody(0).
  • CVE-2022-28615, CVE-2022-28614 - ืžื ื™ืขืช ืฉื™ืจื•ืช ืื• ื’ื™ืฉื” ืœื ืชื•ื ื™ื ื‘ื–ื™ื›ืจื•ืŸ ื”ืชื”ืœื™ืš ืขืงื‘ ืฉื’ื™ืื•ืช ื‘ืคื•ื ืงืฆื™ื•ืช ap_strcmp_match() ื•-ap_rwrite(), ื•ื›ืชื•ืฆืื” ืžื›ืš ืงืจื™ืื” ืžืื–ื•ืจ ืžื—ื•ืฅ ืœื’ื‘ื•ืœ ื”ืžืื’ืจ.
  • CVE-2022-28330 - ื“ืœื™ืคืช ืžื™ื“ืข ืžื—ื•ืฅ ืœืชื—ื•ื ื‘-mod_isapi (ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ืจืง ื‘ืคืœื˜ืคื•ืจืžืช Windows).
  • CVE-2022-26377 - ืžื•ื“ื•ืœ mod_proxy_ajp ืจื’ื™ืฉ ืœื”ืชืงืคื•ืช "ื”ื‘ืจื—ืช ื‘ืงืฉื•ืช HTTP" ืขืœ ืžืขืจื›ื•ืช ื—ื–ื™ืชื™ื•ืช-ื’ื‘ ื”ืžืืคืฉืจื•ืช ืœื—ื“ื•ืจ ืœืชื•ื›ืŸ ืฉืœ ื‘ืงืฉื•ืช ืฉืœ ืžืฉืชืžืฉื™ื ืื—ืจื™ื ื‘ืื•ืชื• ืฉืจืฉื•ืจ ื‘ื™ืŸ ื”ืงืฆื” ื”ืงื“ืžื™ ืœืงืฆื” ื”ืื—ื•ืจื™ .

ื”ืฉื™ื ื•ื™ื™ื ื”ื‘ื•ืœื˜ื™ื ืฉืื™ื ื ื‘ื™ื˜ื—ื•ื ื™ื™ื ื”ื:

  • mod_ssl ื”ื•ืคืš ืืช ืžืฆื‘ SSLFIPS ืœืชื•ืื ืœ-OpenSSL 3.0.
  • ื›ืœื™ ื”ืฉื™ืจื•ืช ab ืžื™ื™ืฉื ืชืžื™ื›ื” ื‘-TLSv1.3 (ื“ื•ืจืฉ ื›ืจื™ื›ื” ืœืกืคืจื™ื™ืช SSL ื”ืชื•ืžื›ืช ื‘ืคืจื•ื˜ื•ืงื•ืœ ื–ื”).
  • ื‘-mod_md, ื”ื ื—ื™ื™ืช MDCertificateAuthority ืžืืคืฉืจืช ื™ื•ืชืจ ืžืฉื CA ืื—ื“ ื•ื›ืชื•ื‘ืช URL. ื ื•ืกืคื• ื”ื ื—ื™ื•ืช ื—ื“ืฉื•ืช: MDRetryDelay (ืžื’ื“ื™ืจ ืืช ื”ืขื™ื›ื•ื‘ ืœืคื ื™ ืฉืœื™ื—ืช ื‘ืงืฉืช ื ื™ืกื™ื•ืŸ ื—ื•ื–ืจ) ื•- MDRetryFailover (ืžื’ื“ื™ืจ ืืช ืžืกืคืจ ื”ื ื™ืกื™ื•ื ื•ืช ื”ื—ื•ื–ืจื™ื ื‘ืžืงืจื” ืฉืœ ื›ืฉืœ ืœืคื ื™ ื‘ื—ื™ืจืช CA ื—ืœื•ืคื™). ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžืฆื‘ "ืื•ื˜ื•ืžื˜ื™" ื‘ืขืช ื”ืฆื’ืช ืขืจื›ื™ื ื‘ืคื•ืจืžื˜ "ืžืคืชื—: ืขืจืš". ืกื™ืคืง ืืช ื”ื™ื›ื•ืœืช ืœื ื”ืœ ืื™ืฉื•ืจื™ื ืขื‘ื•ืจ ืžืฉืชืžืฉื™ VPN ืžืื•ื‘ื˜ื—ื™ื ืฉืœ Tailscale.
  • ืžื•ื“ื•ืœ mod_http2 ื ื•ืงื” ืžืงื•ื“ ืฉืื™ื ื• ื‘ืฉื™ืžื•ืฉ ื•ืœื ื‘ื˜ื•ื—.
  • mod_proxy ืžืกืคืง ื”ืฉืชืงืคื•ืช ืฉืœ ื™ืฆื™ืืช ื”ืจืฉืช ื”ืื—ื•ืจื™ืช ื‘ื”ื•ื“ืขื•ืช ืฉื’ื™ืื” ืฉื ื›ืชื‘ื• ื‘ื™ื•ืžืŸ.
  • ื‘-mod_heartmonitor, ื”ืขืจืš ืฉืœ ื”ืคืจืžื˜ืจ HeartbeatMaxServers ืฉื•ื ื” ืž-0 ืœ-10 (ืืชื—ื•ืœ ืฉืœ 10 ื—ืจื™ืฆื™ ื–ื™ื›ืจื•ืŸ ืžืฉื•ืชืคื™ื).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”