cbcvebase.
CVE-2019-17567
published 2021-06-10

CVE-2019-17567: Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the…

PriorityP351medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
60.27%
99.0th percentile
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server2.4.6 – 2.4.46
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server

Detection & IOCsextracted from sources · hover to see the quote

  • Only Apache HTTP Server configurations using mod_proxy_wstunnel are affected; detect active loading of the module as an exposure indicator
  • Look for HTTP requests on a proxied WebSocket connection that were NOT preceded by a successful HTTP 101 Upgrade response — these would be tunneled through without authentication/authorization checks
  • Upstream patch available for code-level diff and rule authoring at the referenced SVN revision
  • ·Vulnerable version range is Apache HTTP Server 2.4.6 through 2.4.46; fixed in 2.4.48 and later
  • ·The vulnerability is only exploitable when mod_proxy_wstunnel is loaded and configured; disabling the module fully mitigates the issue
  • ·Debian fixed the issue in package version 2.4.48-2 across all active release tracks (bookworm, bullseye, forky, sid, trixie)

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_msrc5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.