CVE-2005-2090
Description
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a Transfer-Encoding: chunked header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka HTTP Request Smuggling.
Risk Information
Base Score
8.6
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N/E:P/RL:U/RC:C
EPSS Score
Exploitation Probability
81.971
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Update Tomcat to 9.5.14 | Windows |
| Update Tomcat to 9.5.5 | Windows |
| Update Tomcat to 9.5.7 | Windows |
| Update Tomcat to 9.5.8 | Windows |
| Update Tomcat to 9.6.10 | Windows |
| Update Tomcat to 9.6.3 | Windows |
| Update Tomcat to 9.6.4 | Windows |
| Update Tomcat to 9.6.7 | Windows |
| Update Tomcat to 9.6.8 | Windows |
| Update Tomcat to 2.4.5 | Windows |
| Update Tomcat to 3.0.14 | Windows |
| Update Apache Tomcat to 5.5.22 | Windows |
| Update Apache Tomcat to 5.5.23 | Windows |
| Vulnerabilities CVE-2005-2090 are affected in Apache - tomcat 5.0.19 | Windows |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-1.1-8jpp.1.0.2.el5.i386.rpm | Linux |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-1.1-8jpp.1.0.2.el5.x86_64.rpm | Linux |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-javadoc-1.1-8jpp.1.0.2.el5.i386.rpm | Linux |
| (RHSA-2007:0327) Important: tomcat security update jakarta-commons-modeler-javadoc-1.1-8jpp.1.0.2.el5.x86_64.rpm | Linux |
| Update Tomcat to 9.5.14 (For Linux) | Linux |
| Update Tomcat to 9.5.5 (For Linux) | Linux |
| Update Tomcat to 9.5.7 (For Linux) | Linux |
| Update Tomcat to 9.5.8 (For Linux) | Linux |
| Update Tomcat to 9.6.10 (For Linux) | Linux |
| Update Tomcat to 9.6.3 (For Linux) | Linux |
| Update Tomcat to 9.6.4 (For Linux) | Linux |
| Update Tomcat to 9.6.7 (For Linux) | Linux |
| Update Tomcat to 9.6.8 (For Linux) | Linux |
| Update Tomcat to 2.4.5 (For Linux) | Linux |
| Update Tomcat to 3.0.14 (For Linux) | Linux |
| Update Apache Tomcat to 5.5.22 (For Linux) | Linux |
| Update Apache Tomcat to 5.5.23 (For Linux) | Linux |
| Vulnerabilities CVE-2005-2090 are affected in Apache - tomcat for Linux 5.0.19 | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234