5.3
CVSSv3

CVE-2019-17567

Published: 10/06/2021 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 447
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apache http server

fedoraproject fedora 34

fedoraproject fedora 35

oracle instantis enterprisetrack 17.1

oracle instantis enterprisetrack 17.2

oracle instantis enterprisetrack 17.3

oracle enterprise manager ops center 12.4.0.0

oracle zfs storage appliance kit 8.8

Vendor Advisories

A flaw was found in Apache httpd The mod_proxy_wstunnel module tunnels non-upgraded connections (CVE-2019-17567) A flaw was found in HTTPd In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows The highest threat from this vulnerability is to system availability (CVE-2020-13938) A flaw was found In Apache httpd ...
A flaw was found in Apache httpd The mod_proxy_wstunnel module tunnels non-upgraded connections (CVE-2019-17567) A flaw was found in HTTPd In some Apache HTTP Server versions, unprivileged local users can stop HTTPd on Windows The highest threat from this vulnerability is to system availability (CVE-2020-13938) A flaw was found In Apache httpd ...
In Apache HTTP Server versions 246 to 2446, mod_proxy_wstunnel configured on an URL that is not necessarily upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured ...
A vulnerability (CVE-2019-17567) exists in Cosminexus HTTP Server Affected products and versions are listed below Please upgrade your version to the appropriate version ...