CVE-2019-17567: mod_proxy_wstunnel tunneling of non Upgraded connections
Published Jun 1, 2021
·Updated
Apache HTTP Server versions 2.4.6 to 2.4.46 modproxywstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
Other sources
modproxywstunnel tunneling of non Upgraded connection in Apache httpd before 2.4.48.
— Red Hat
Affected Software
9 affected componentsFixes available
redhat/httpd<2.4.47
2.4.47
Apache HTTP Server>=2.4.6<=2.4.46
Fedoraproject Fedora=34
Fedoraproject Fedora=35
Oracle Enterprise Manager Ops Center=12.4.0.0
Oracle Instantis Enterprisetrack=17.1
Oracle Instantis Enterprisetrack=17.2
Oracle Instantis Enterprisetrack=17.3
Oracle ZFS Storage Appliance Kit=8.8
Event History
Jun 1, 2021
Data Sourced
via Red Hat·06:50 PM
DescriptionSeverityAffected Software
Jun 10, 2021
CVE Published
via MITRE·07:10 AM
Data Sourced
via MITRE·07:10 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2019-17567.
2
What is the severity of CVE-2019-17567?
The severity of CVE-2019-17567 is medium.
3
Which versions of Apache HTTP Server are affected?
Versions 2.4.6 to 2.4.46 of Apache HTTP Server are affected.
4
How can I fix CVE-2019-17567?
To fix CVE-2019-17567, upgrade to version 2.4.47 of Apache HTTP Server.
5
Where can I find more information about CVE-2019-17567?
You can find more information about CVE-2019-17567 at the following references: [1] [2] [3].