CVE-2019-17569

Description

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

Risk Information

Base Score
4.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
6.063

Associated Vulnerability

VulnerabilityOS Platform
GhostCat: Vulnerabilities CVE-2020-1938,CVE-2020-1935,CVE-2019-17569 are fixed in 11 February 2019 Fixed in Apache Tomcat 9.0.31Windows
GhostCat: Vulnerabilities CVE-2020-1938,CVE-2020-1935,CVE-2019-17569 are fixed in 11 February 2020 Fixed in Apache Tomcat 8.5.51Windows
GhostCat: Vulnerabilities CVE-2020-1938,CVE-2020-1935,CVE-2019-17569 are fixed in 14 February 2020 Fixed in Apache Tomcat 7.0.100Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.3.0Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 7.0.4.0Windows
Vulnerabilities CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat 7.0.100Windows
Vulnerabilities CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat 8.5.51Windows
Vulnerabilities CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat 9.0.31Windows
Vulnerabilities CVE-2020-1938,CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat-embed-core 9.0.31Windows
Vulnerabilities CVE-2020-1938,CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat-embed-core 8.5.51Windows
Vulnerabilities CVE-2020-1938,CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat-embed-core 7.0.100Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.3Windows
Multiple Vulnerabilities are affected in IBM UrbanCode Deploy 6.2.7.4Windows
Multiple Vulnerabilities are affected in IBM Tivoli Application Dependency Discovery Manager 7.3.0Windows
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-admin-webapps-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-docs-webapp-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-admin-webapps-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-el-3_0-api-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-docs-webapp-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-javadoc-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-el-3_0-api-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-jsp-2_3-api-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-javadoc-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-lib-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-jsp-2_3-api-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-servlet-4_0-api-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-lib-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP4 ) tomcat-webapps-9.0.31-3.25.1.noarch.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-servlet-4_0-api-9.0.31-3.25.1.noarch_SP5.rpmLinux
SUSE-SU-2020:0632-1(SUSE Linux Enterprise Server 12-SP5 ) tomcat-webapps-9.0.31-3.25.1.noarch_SP5.rpmLinux
tomcat8 security update(DSA-4673-1) tomcat8_8.5.54-0+deb9u1_all.debLinux
tomcat9 security update(DSA-4680-1) tomcat9_9.0.31-1~deb10u1_all.debLinux
GhostCat: Vulnerabilities CVE-2020-1938,CVE-2020-1935,CVE-2019-17569 are fixed in 11 February 2019 Fixed in Apache Tomcat 9.0.31 (For Linux)Linux
GhostCat: Vulnerabilities CVE-2020-1938,CVE-2020-1935,CVE-2019-17569 are fixed in 11 February 2020 Fixed in Apache Tomcat 8.5.51 (For Linux)Linux
GhostCat: Vulnerabilities CVE-2020-1938,CVE-2020-1935,CVE-2019-17569 are fixed in 14 February 2020 Fixed in Apache Tomcat 7.0.100 (For Linux)Linux
Vulnerabilities CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat for Linux 7.0.100Linux
Vulnerabilities CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat for Linux 8.5.51Linux
Vulnerabilities CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat for Linux 9.0.31Linux
Vulnerabilities CVE-2020-1938,CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat-embed-core for Linux 9.0.31Linux
Vulnerabilities CVE-2020-1938,CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat-embed-core for Linux 8.5.51Linux
Vulnerabilities CVE-2020-1938,CVE-2019-17569,CVE-2020-1935 are fixed in Apache - tomcat-embed-core for Linux 7.0.100Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234