Security restrictions bypass in Apache HTTP Server - CVE-2019-17567
Published: June 3, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to unspecified error within the mod_proxy_wstunnel and mod_proxy_http modules. If mod_proxy_wstunnel is configured on an URL that is not necessarily Upgraded by the origin server and is tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
Affected software
Amazon Linux AMI
Gentoo Linux
IBM i
Slackware Linux
openEuler
Fedora
jbcs-httpd24-openssl-pkcs11 (Red Hat package)
jbcs-httpd24-openssl-chil (Red Hat package)
jbcs-httpd24-apr-util (Red Hat package)
jbcs-httpd24-apr (Red Hat package)
jbcs-httpd24-mod_http2 (Red Hat package)
jbcs-httpd24-nghttp2 (Red Hat package)
jbcs-httpd24-mod_md (Red Hat package)
jbcs-httpd24-httpd (Red Hat package)
jbcs-httpd24-mod_security (Red Hat package)
jbcs-httpd24-curl (Red Hat package)
httpd-devel
httpd-help
httpd-filesystem
httpd
mod_md
httpd-debuginfo
httpd-tools
httpd-debugsource
mod_ldap
mod_session
mod_ssl
mod_proxy_html
JBoss Core Services
EasyApache
IBM Rational Build Forge
Maximo Application Suite - IoT Component
How to mitigate CVE-2019-17567
jbcs-httpd24-openssl-pkcs11 (Red Hat package) - addressed in versions 0.4.10-22.el8jbcs, 0.4.10-22.jbcs.el7
jbcs-httpd24-openssl-chil (Red Hat package) - addressed in versions 1.0.0-7.el8jbcs, 1.0.0-7.jbcs.el7
jbcs-httpd24-apr-util (Red Hat package) - addressed in versions 1.6.1-84.el8jbcs, 1.6.1-84.jbcs.el7
jbcs-httpd24-apr (Red Hat package) - addressed in versions 1.6.3-107.el8jbcs, 1.6.3-107.jbcs.el7
jbcs-httpd24-mod_http2 (Red Hat package) - addressed in versions 1.15.7-21.el8jbcs, 1.15.7-21.jbcs.el7
jbcs-httpd24-nghttp2 (Red Hat package) - addressed in versions 1.39.2-39.el8jbcs, 1.39.2-39.jbcs.el7
jbcs-httpd24-mod_md (Red Hat package) - addressed in versions 2.0.8-40.el8jbcs, 2.0.8-40.jbcs.el7
JBoss Core Services - update to 2.4.37 SP10
jbcs-httpd24-httpd (Red Hat package) - addressed in versions 2.4.37-78.el8jbcs, 2.4.37-78.jbcs.el7
jbcs-httpd24-mod_security (Red Hat package) - addressed in versions 2.9.2-67.GA.el8jbcs, 2.9.2-67.GA.jbcs.el7
EasyApache - update to 4 2021-6-2
jbcs-httpd24-curl (Red Hat package) - addressed in versions 7.78.0-2.el8jbcs, 7.78.0-2.jbcs.el7
IBM Rational Build Forge - update to 8.0.0.21
httpd-devel - update to 2.4.43-22
httpd-help - update to 2.4.43-22
httpd-filesystem - update to 2.4.43-22
httpd - update to 2.4.43-22
mod_md - update to 2.4.43-22
httpd-debuginfo - update to 2.4.43-22
httpd-tools - update to 2.4.43-22
httpd-debugsource - update to 2.4.43-22
mod_ldap - update to 2.4.43-22
mod_session - update to 2.4.43-22
mod_ssl - update to 2.4.43-22
mod_proxy_html - update to 2.4.43-22
httpd - addressed in versions 2.4.49-1.fc34, 2.4.49-1.fc35
Maximo Application Suite - IoT Component - addressed in versions 8.7.20, 8.8.16, 9.0.6
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache HTTP Server
- cPanel update for EasyApache
- Slackware Linux update for httpd
- Amazon Linux AMI update for httpd24
- Gentoo update for Apache
- Multiple vulnerabilities in Red Hat JBoss Core Services Apache HTTP Server
- Multiple vulnerabilities in IBM i
- openEuler 20.03 LTS SP3 update for httpd
- openEuler 20.03 LTS SP1 update for httpd
- Fedora 34 update for httpd
- Fedora 35 update for httpd
- Multiple vulnerabilities in IBM Maximo Application Suite - IoT Component
- Multiple vulnerabilities in IBM Rational Build Forge