← Back

CVE-2021-33037

nvd nist
Published: Jul 12, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

Affected (42)

Show all products
2 products
Tomcat
Tomee
1 product
Debian Linux
18 products
Agile Plm
Communications Policy Management
Graph Server And Client
Healthcare Translational Research
Instantis Enterprisetrack
Managed File Transfer
Mysql Enterprise Monitor
Sd Wan Edge
Secure Global Desktop
Utilities Testing Accelerator
1 product
Epolicy Orchestrator
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Apache
After 10.0.0 to 10.0.6
After 9.0.0 to 9.0.46
From 8.5.0 to 8.5.66
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 8.0.6
Configuration C
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 9.0
Configuration D
24 vulnerable
Configuration E
12 vulnerable
Vulnerable SoftwareAffected Versions
Mcafee
Before 5.10.0
Version 5.10.0
Version 5.10.0 update_10
Version 5.10.0 update_1
Version 5.10.0 update_2
Version 5.10.0 update_3
Version 5.10.0 update_4
Version 5.10.0 update_5
Version 5.10.0 update_6
Version 5.10.0 update_7
Version 5.10.0 update_8
Version 5.10.0 update_9

References (32)

Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Mailing ListThird Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
Third Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: security@apache.org
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory

Timeline

No history available yet.