← Back

CVE-2019-17567

nvd nist
Published: Jun 10, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

Affected (8)

1 product
Http Server
1 product
Fedora
3 products
Enterprise Manager Ops Center
Instantis Enterprisetrack
Zfs Storage Appliance Kit
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.4.6 to 2.4.46
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 34
Version 35
Configuration C
5 vulnerable
Vulnerable SoftwareAffected Versions
Version 12.4.0.0
Oracle
Version 17.1
Version 17.2
Version 17.3
Version 8.8

References (22)

Source: security@apache.org
Release NotesVendor Advisory
Source: security@apache.org
Mailing ListMitigationThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListMitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.