Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2019-17569

 

Inconsistent interpretation of HTTP requests in Apache Tomcat - CVE-2019-17569

Published: March 6, 2020 / Updated: April 23, 2020


Vulnerability identifier: #VU25806
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17569
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform HTTP request smuggling attack.

The vulnerability exists due to improper input validation when processing a Transfer-Encoding headers. A remote attacker can send a specially crafted HTTP request and perform HTTP request smuggling attack.

Affected software

Apache Tomcat
Cloud Foundry UAA
Amazon Linux AMI
Oracle Solaris
Opensuse
tomcat8 (Debian package)
tomcat9 (Debian package)
CF Deployment
Oracle Database Server

How to mitigate CVE-2019-17569

Install updates from vendor's website.

Apache Tomcat - addressed in versions 7.0.100, 8.5.51, 9.0.31
tomcat8 (Debian package) - update to 8.5.54-0+deb9u1
tomcat9 (Debian package) - update to 9.0.31-1~deb10u1
CF Deployment - update to 12.40.0
Cloud Foundry UAA - update to 74.16.0

External References

Related Security Bulletins