← Back

CVE-2021-33037

nvd nist
Published: Jul 12, 2021Modified: Aug 25, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

Affected (42)

Show all products
2 products
Tomcat
Tomee
1 product
Debian Linux
18 products
1 product
Epolicy Orchestrator
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
After 10.0.0 to 10.0.6
After 9.0.0 to 9.0.46
From 8.5.0 to 8.5.66
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0.6
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration D
24 vulnerable
Configuration E
12 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Before 5.10.0
Version 5.10.0
Version 5.10.0 update_10
Version 5.10.0 update_1
Version 5.10.0 update_2
Version 5.10.0 update_3
Version 5.10.0 update_4
Version 5.10.0 update_5
Version 5.10.0 update_6
Version 5.10.0 update_7
Version 5.10.0 update_8
Version 5.10.0 update_9

References (32)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.