Security restrictions bypass in Apache HTTP Server - CVE-2019-17567

 

Security restrictions bypass in Apache HTTP Server - CVE-2019-17567

Published: June 3, 2021


Vulnerability identifier: #VU53780
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-17567
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass implemented security restrictions.

The vulnerability exists due to unspecified error within the mod_proxy_wstunnel and mod_proxy_http modules. If mod_proxy_wstunnel is configured on an URL that is not necessarily Upgraded by the origin server and is tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.


Affected software

Apache HTTP Server
Amazon Linux AMI
Gentoo Linux
IBM i
Slackware Linux
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
httpd-devel
httpd-help
httpd-filesystem
httpd
mod_md
httpd-debuginfo
httpd-tools
httpd-debugsource
mod_ldap
mod_session
mod_ssl
mod_proxy_html
JBoss Core Services
EasyApache
IBM Rational Build Forge
Maximo Application Suite - IoT Component

How to mitigate CVE-2019-17567

Install updates from vendor's website.

Apache HTTP Server - update to 2.4.47
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
EasyApache - update to 4 2021-6-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
IBM Rational Build Forge - update to 8.0.0.21
httpd-devel - update to 2.4.43-22
httpd-help - update to 2.4.43-22
httpd-filesystem - update to 2.4.43-22
httpd - update to 2.4.43-22
mod_md - update to 2.4.43-22
httpd-debuginfo - update to 2.4.43-22
httpd-tools - update to 2.4.43-22
httpd-debugsource - update to 2.4.43-22
mod_ldap - update to 2.4.43-22
mod_session - update to 2.4.43-22
mod_ssl - update to 2.4.43-22
mod_proxy_html - update to 2.4.43-22
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6

External References

Related Security Bulletins