CVE-2022-24963 is a critical integer overflow or wraparound vulnerability in the Apache Portable Runtime (APR) version 1.7.0. This flaw, specifically within apr_encode functions, allows an attacker to write beyond buffer boundaries. With a CVSS score of 9.8, it presents a severe risk, enabling unauthenticated remote attackers to achieve high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.0CPE matchmatch criteria | cpe:2.3:a:apache:portable_runtime:1.7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.