CVE-2019-17567
Summary
| CVE | CVE-2019-17567 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-10 07:15:00 UTC |
| Updated | 2023-11-07 03:06:00 UTC |
| Description | Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured. |
Risk And Classification
Problem Types: CWE-444
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Http Server | All | All | All | All |
| Operating System | Fedoraproject | Fedora | 34 | All | All | All |
| Operating System | Fedoraproject | Fedora | 35 | All | All | All |
| Application | Oracle | Enterprise Manager Ops Center | 12.4.0.0 | All | All | All |
| Application | Oracle | Instantis Enterprisetrack | 17.1 | All | All | All |
| Application | Oracle | Instantis Enterprisetrack | 17.2 | All | All | All |
| Application | Oracle | Instantis Enterprisetrack | 17.3 | All | All | All |
| Application | Oracle | Zfs Storage Appliance Kit | 8.8 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pony Mail! | MLIST | lists.apache.org | |
| Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project | CONFIRM | httpd.apache.org | |
| Pony Mail! | CONFIRM | lists.apache.org | |
| [SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| [SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Pony Mail! | lists.apache.org | ||
| oss-security - CVE-2019-17567: Apache httpd: mod_proxy_wstunnel tunneling of non Upgraded connections | MLIST | www.openwall.com | |
| June 2021 Apache HTTP Server Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| Apache: Multiple vulnerabilities (GLSA 202107-38) — Gentoo security | GENTOO | security.gentoo.org | |
| Pony Mail! | MLIST | lists.apache.org | |
| [httpd-dev] 20210610 Re: svn commit: r1890598 - in /httpd/site/trunk/content/security/json: CVE-2019-17567.json CVE-2020-13938.json CVE-2020-13950.json CVE-2020-35452.json CVE-2021-26690.json CVE-2021-26691.json CVE-2021-30641.json CVE-2021-31618.json | lists.apache.org | ||
| [SECURITY] Fedora 35 Update: httpd-2.4.49-1.fc35 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 34 Update: httpd-2.4.49-1.fc34 - package-announce - Fedora Mailing-Lists | FEDORA | lists.fedoraproject.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Reported by Mikhail Egorov (<0ang3el gmail.com>)
Legacy QID Mappings
- 239865 Red Hat Update for red hat jboss core services apache Hypertext Transfer Protocol (HTTP) server 2.4.37 sp10 (RHSA-2021:4614)
- 281910 Fedora Security Update for Hypertext Transfer Protocol Daemon (HTTPd) (FEDORA-2021-dce7e7738e)
- 352395 Amazon Linux Security Advisory for httpd: ALAS2-2021-1659
- 352462 Amazon Linux Security Advisory for httpd: ALAS2-2021-1674
- 352477 Amazon Linux Security Advisory for httpd24: ALAS-2021-1514
- 690107 Free Berkeley Software Distribution (FreeBSD) Security Update for apache httpd (cce76eca-ca16-11eb-9b84-d4c9ef517024)
- 710030 Gentoo Linux Apache Multiple vulnerabilities (GLSA 202107-38)
- 730109 Apache HTTP Server Multiple Vulnerabilities
- 900137 CBL-Mariner Linux Security Update for httpd 2.4.46
- 901662 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (6473-1)
- 903538 Common Base Linux Mariner (CBL-Mariner) Security Update for httpd (4349)