PT-2021-5806 · Apache+2 · Apache Http Server+2

Published

2021-05-20

·

Updated

2024-06-10

·

CVE-2019-17567

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache HTTP Server versions 2.4.6 through 2.4.46
Description The issue is related to the handling of HTTP requests in the Apache HTTP Server. Specifically, when mod proxy wstunnel is configured on a URL that is not necessarily upgraded by the origin server, it tunnels the whole connection regardless, allowing subsequent requests on the same connection to pass through with no HTTP validation, authentication, or authorization. This could potentially allow a remote attacker to impact the integrity of data.
Recommendations For Apache HTTP Server versions 2.4.6 through 2.4.46, consider disabling the mod proxy wstunnel module until a patch is available to prevent unauthorized access. Restrict access to sensitive areas of the server to minimize the risk of exploitation. As a temporary workaround, consider implementing additional validation and authentication mechanisms for incoming requests to mitigate the risk. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1838
ALT-PU-2021-2035
ALT-PU-2021-2339
AZL-6473
BDU:2022-00270
CVE-2019-17567
DLA-3818-1
MGASA-2021-0265
OESA-2023-1222
OESA-2023-1230
RHSA-2021:4614

Affected Products

Alt Linux
Apache Http Server
Astra Linux