cbcvebase.
CVE-2019-17567
published 2021-06-10

CVE-2019-17567: Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

Affected

35 ranges· showing 25
VendorProductVersion rangeFixed in
apachehttp_server2.4.6 – 2.4.46
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server
apache_software_foundationapache_http_server

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM