CVE-2021-33037
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD
Description
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
Affected (42)
Products: Apache: Tomcat, Tomee · Debian: Debian Linux · Oracle: Agile Plm, Communications Cloud Native Core Policy, Communications Cloud Native Core Service Communication Proxy, Communications Diameter Signaling Router, Communications Instant Messaging Server, Communications Policy Management, Communications Pricing Design Center, Communications Session Report Manager, Communications Session Route Manager, Graph Server And Client, Healthcare Translational Research, Hospitality Cruise Shipboard Property Management System, Instantis Enterprisetrack, Managed File Transfer, Mysql Enterprise Monitor, Sd Wan Edge, Secure Global Desktop, Utilities Testing Accelerator · +1 more
Show all products
Apache: Tomcat, Tomee · Debian: Debian Linux · Oracle: Agile Plm, Communications Cloud Native Core Policy, Communications Cloud Native Core Service Communication Proxy, Communications Diameter Signaling Router, Communications Instant Messaging Server, Communications Policy Management, Communications Pricing Design Center, Communications Session Report Manager, Communications Session Route Manager, Graph Server And Client, Healthcare Translational Research, Hospitality Cruise Shipboard Property Management System, Instantis Enterprisetrack, Managed File Transfer, Mysql Enterprise Monitor, Sd Wan Edge, Secure Global Desktop, Utilities Testing Accelerator · Mcafee: Epolicy Orchestrator
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.3.6 | |
| Version 1.14.0 | |
| Version 1.14.0 | |
| From 8.0.0.0 to 8.5.0.2 | |
| Version 10.0.1.5.0 | |
| Version 12.5.0 | |
| Version 12.0.0.3.0 | |
| From 8.0.0 to 8.2.4.0 | |
| From 8.0.0 to 8.2.4 | |
| Before 21.4 | |
| Version 4.1.0 | |
| Version 20.1.0 | |
| Version 17.1 | |
| Version 12.2.1.3.0 | |
| Up to 8.0.25 | |
| Version 9.0 | |
| Version 5.6 | |
| Version 6.0.0.1.1 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 5.10.0 |
References (32)
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListVendor Advisory
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Timeline
No history available yet.