CVE-2021-35233: HTTP TRACK & TRACE Methods Enabled
The HTTP TRACK & TRACE methods were enabled in Kiwi Syslog Server 9.7.1 and earlier. These methods are intended for diagnostic purposes only. If enabled, the web server will respond to requests that use these methods by returning exact HTTP request that was received in the response to the client. This may lead to the disclosure of sensitive information such as internal authentication headers appended by reverse proxies.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-35233?
CVE-2021-35233 is a vulnerability in Kiwi Syslog Server 9.7.1 and earlier where the HTTP TRACK & TRACE methods are enabled, allowing the web server to respond to requests by returning the exact HTTP request received.
What is the severity of CVE-2021-35233?
The severity of CVE-2021-35233 is medium with a severity value of 5.3.
How do I fix CVE-2021-35233?
To fix CVE-2021-35233, upgrade to Kiwi Syslog Server version 9.7.2 or later.
What is the Common Weakness Enumeration (CWE) for CVE-2021-35233?
The Common Weakness Enumeration (CWE) for CVE-2021-35233 is CWE-16.
Where can I find more information about CVE-2021-35233?
You can find more information about CVE-2021-35233 in the SolarWinds documentation and security advisories.