PT-2020-4108 · Apache+1 · Apache Tomcat+1

Published

2020-02-11

·

Updated

2024-06-15

·

CVE-2019-17569

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Apache Tomcat versions 7.0.98 through 7.0.99 Apache Tomcat versions 8.5.48 through 8.5.50 Apache Tomcat versions 9.0.28 through 9.0.30
Description: The issue is related to the incorrect processing of invalid Transfer-Encoding headers, which can lead to HTTP Request Smuggling if Apache Tomcat is located behind a reverse proxy that incorrectly handles the invalid header. This can potentially allow a remote attacker to impact the confidentiality and integrity of protected information. The vulnerability is associated with inconsistent interpretation and handling of HTTP requests.
Recommendations: For Apache Tomcat versions 7.0.98 through 7.0.99, update to a version that includes the fix for this issue. For Apache Tomcat versions 8.5.48 through 8.5.50, update to a version that includes the fix for this issue. For Apache Tomcat versions 9.0.28 through 9.0.30, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the server when it is located behind a reverse proxy to minimize the risk of exploitation.

Exploit

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04511
BDU:2021-01013
CVE-2019-17569
DLA-2133-1
DSA-4673-1
DSA-4680-1
GHSA-767J-JFH2-JVRC
MGASA-2020-0138
OPENSUSE-SU-2020:0345-1
OPENSUSE-SU-2020_0345-1
OPENSUSE-SU-2024:11468-1
OPENSUSE-SU-2024:13441-1
RHSA-2020:1520
SUSE-SU-2020:0598-1
SUSE-SU-2020:0631-1
SUSE-SU-2020:0632-1
SUSE-SU-2020:1497-1
SUSE-SU-2020:1498-1
SUSE-SU-2020_1497-1
SUSE-SU-2020_1498-1

Affected Products

Apache Tomcat
Suse