7.8
CVSSv2

CVE-2019-9514

Published: 13/08/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 695
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

it exists that Twisted incorrectly validated or sanitized certain URIs or HTTP methods. A remote attacker could use this issue to inject invalid characters and possibly perform header injection attacks. (CVE-2019-12387)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple swiftnio

apache traffic server

debian debian linux 10.0

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

debian debian linux 9.0

synology skynas -

synology diskstation manager 6.2

synology vs960hd_firmware -

fedoraproject fedora 29

fedoraproject fedora 30

opensuse leap 15.0

opensuse leap 15.1

redhat enterprise linux workstation 7.0

redhat enterprise linux server 7.0

redhat software collections 1.0

redhat openshift container platform 3.9

redhat openshift container platform 3.11

redhat openshift container platform 3.10

redhat jboss core services 1.0

redhat enterprise linux 8.0

redhat jboss enterprise application platform 7.2.0

redhat single sign-on 7.3

redhat developer tools 1.0

redhat openshift container platform 4.1

redhat openshift container platform 4.2

redhat quay 3.0.0

redhat enterprise linux eus 8.1

redhat openshift service mesh 1.0

redhat openstack 14

redhat jboss enterprise application platform 7.3.0

oracle graalvm 19.2.0

mcafee web gateway

netapp cloud insights -

netapp trident -

f5 big-ip local traffic manager

nodejs node.js

Vendor Advisories

Several security issues were fixed in Twisted ...
Debian Bug report logs - #934954 golang-113: CVE-2019-14809 Package: src:golang-113; Maintainer for src:golang-113 is Go Compiler Team <team+go-compiler@trackerdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 17 Aug 2019 08:54:00 UTC Severity: grave Tags: security, upstream Found in ...
Debian Bug report logs - #934886 CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 Package: src:h2o; Maintainer for src:h2o is Apollon Oikonomopoulos <apoikos@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 16 Aug 2019 08:06:02 UTC Severity: grave Tags: security, upstream Forwarded to git ...
Debian Bug report logs - #934887 CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 Package: src:trafficserver; Maintainer for src:trafficserver is Jean Baptiste Favre <debian@jbfavreorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 16 Aug 2019 08:06:06 UTC Severity: grave Tags: security, upstream Found in v ...
net/url in Go before 11113 and 112x before 1128 mishandles malformed hosts in URLs, leading to an authorization bypass in some applications This is related to a Host field with a suffix appearing in neither Hostname() nor Port(), and is related to a non-numeric port number For example, an attacker can compose a crafted javascript:// URL tha ...
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queue of responses Depending on how efficiently this data is queued, this can consume excess CPU, memory, or both (CVE-2019-9512) Some HTTP/2 implementat ...
Multiple vulnerabilities were discovered in Nodejs, which could result in denial of service or HTTP request smuggling For the stable distribution (buster), these problems have been fixed in version 10190~dfsg1-1 We recommend that you upgrade your nodejs packages For the detailed security status of nodejs please refer to its security tracker p ...
Three vulnerabilities have been discovered in the Go programming language; "net/url" accepted some invalid hosts in URLs which could result in authorisation bypass in some applications and the HTTP/2 implementation was susceptible to denial of service For the stable distribution (buster), these problems have been fixed in version 1116-1+deb10u1 ...
Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service For the stable distribution (buster), these problems have been fixed in version 225+dfsg2-2+deb10u1 We recommend that you upgrade your h2o packages For the detailed security status of h2o please refer to its security tracker ...
Several vulnerabilities were discovered in the HTTP/2 code of Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service The fixes are too intrusive to backport to the version in the oldstable distribution (stretch) An upgrade to Debian stable (buster) is recommended instead For the stable distribution (bu ...
Impact: Important Public Date: 2019-08-13 CWE: CWE-400 Bugzilla: 1735744: CVE-2019-9514 istio/envoy: HT ...
An issue has been found in several HTTP/2 implementations, where the attacker opens a number of streams and sends an invalid request over each stream that should solicit a stream of RST_STREAM frames from the peer Depending on how the peer queues the RST_STREAM frames, this can consume excess memory, CPU, or both, potentially leading to a denial o ...
Synopsis Important: Red Hat Single Sign-On 735 security update on RHEL 6 Type/Severity Security Advisory: Important Topic New Red Hat Single Sign-On 735 packages are now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: OpenShift Container Platform 310 security update Type/Severity Security Advisory: Important Topic An update for atomic-openshift is now available for Red Hat OpenShift Container Platform 310Red Hat Product Security has rated this update as having a security impact of Important A Comm ...
Synopsis Important: OpenShift Container Platform 41 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scorin ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72Red Hat Product Security has rated this update as having a security impact of Important A ...
Synopsis Important: Red Hat Process Automation Manager 780 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scori ...
Synopsis Important: Red Hat Decision Manager 780 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: OpenShift Container Platform 4120 golang security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabil ...
Synopsis Important: Red Hat OpenShift Enterprise 4115 gRPC security update Type/Severity Security Advisory: Important Topic An update for gRPC, included in multus-cni-container, operator-lifecycle-manager-container, and operator-registry-container is now available for Red Hat OpenShift Container Platform ...
Synopsis Important: rh-nodejs10-nodejs security update Type/Severity Security Advisory: Important Topic An update for rh-nodejs10-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: rh-nodejs8-nodejs security update Type/Severity Security Advisory: Important Topic An update for rh-nodejs8-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sys ...
Synopsis Important: Red Hat Single Sign-On 735 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 73 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: Red Hat Single Sign-On 735 security update on RHEL 7 Type/Severity Security Advisory: Important Topic New Red Hat Single Sign-On 735 packages are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: OpenShift Container Platform 4118 gRPC security update Type/Severity Security Advisory: Important Topic An update for gRPC, included in sriov-network-device-plugin-container, is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat Data Grid 733 security update Type/Severity Security Advisory: Important Topic An update for Red Hat Data Grid is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis Important: Red Hat Single Sign-On 735 security update on RHEL 8 Type/Severity Security Advisory: Important Topic New Red Hat Single Sign-On 735 packages are now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: OpenShift Container Platform 311 HTTP/2 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Container Platform 311Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
Synopsis Important: OpenShift Container Platform 4114 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: OpenShift Container Platform 39 security update Type/Severity Security Advisory: Important Topic An security update is now available for Red Hat OpenShift Container Platform 39Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabili ...
Synopsis Important: Red Hat Quay v311 security update Type/Severity Security Advisory: Important Topic Updated Quay packages that fix several bugs and add various enhancements are now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability ...
Synopsis Important: containernetworking-plugins security update Type/Severity Security Advisory: Important Topic An update for containernetworking-plugins is now available for Red Hat Enterprise Linux 7 ExtrasRed Hat Product Security has rated this update as having a security impact of Important A Common ...
Synopsis Important: container-tools:rhel8 security and bug fix update Type/Severity Security Advisory: Important Topic An update for the container-tools:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Com ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 on RHEL 7 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as ...
Synopsis Important: go-toolset-111 and go-toolset-111-golang security update Type/Severity Security Advisory: Important Topic An update for go-toolset-111 and go-toolset-111-golang is now available for Red Hat Developer ToolsRed Hat Product Security has rated this update as having a security impact of ...
Synopsis Important: container-tools:10 security update Type/Severity Security Advisory: Important Topic An update for the container-tools:10 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerabilit ...
Synopsis Important: Red Hat Fuse 750 security update Type/Severity Security Advisory: Important Topic A minor version update (from 74 to 75) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Synopsis Important: Red Hat Fuse 760 security update Type/Severity Security Advisory: Important Topic A minor version update (from 75 to 76) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 on RHEL 8 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72 for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 on RHEL 6 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as ...
Synopsis Important: EAP Continuous Delivery Technical Preview Release 18 security update Type/Severity Security Advisory: Important Topic This is a security update for JBoss EAP Continuous Delivery 180Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Synopsis Important: Red Hat AMQ Broker 76 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 76 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: OpenShift Container Platform 42 security update Type/Severity Security Advisory: Important Topic An update for apb, containernetworking-plugins, and golang-github-prometheus-promu is now available for Red Hat OpenShift Container Platform 42Red Hat Product Security has rated this updat ...
Synopsis Important: Red Hat OpenShift Container Platform 41 openshift RPM security update Type/Severity Security Advisory: Important Topic An update for the openshift and atomic-enterprise-service-catalog packages is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has ra ...
Synopsis Important: nodejs:10 security update Type/Severity Security Advisory: Important Topic An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CV ...
Synopsis Important: Red Hat JBoss Fuse/A-MQ 63 R14 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Fuse 63 and Red Hat JBoss A-MQ 63Red Hat Product Security has rated this update as having a security impact of Important A Common ...
Synopsis Important: Red Hat AMQ Broker 743 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 743 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability ...
Synopsis Important: go-toolset:rhel8 security and bug fix update Type/Severity Security Advisory: Important Topic An update for the go-toolset:rhel8 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulner ...
Synopsis Important: Red Hat build of Thorntail 251 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of ThorntailRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-08-13-5 SwiftNIO HTTP/2 150 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product ...

Recent Articles

Microsoft Patch Tuesday – August 2019
Symantec Threat Intelligence Blog • Ratheesh PM • 14 Aug 2024

This month the vendor has patched 93 vulnerabilities, 27 of which are rated Critical.

Posted: 14 Aug, 201926 Min ReadThreat Intelligence SubscribeFollowtwitterfacebooklinkedinMicrosoft Patch Tuesday – August 2019This month the vendor has patched 93 vulnerabilities, 27 of which are rated Critical.This month Microsoft has patched 93 vulnerabilities, 27 of which are rated Critical. As always, customers are advised to follow these security best practices: Install vendor patches as soon as they are available. Run all sof...

References

CWE-770https://kb.cert.org/vuls/id/605641/https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.mdhttps://seclists.org/bugtraq/2019/Aug/24http://seclists.org/fulldisclosure/2019/Aug/16https://www.synology.com/security/advisory/Synology_SA_19_33https://seclists.org/bugtraq/2019/Aug/31https://www.debian.org/security/2019/dsa-4503https://support.f5.com/csp/article/K01988340http://www.openwall.com/lists/oss-security/2019/08/20/1https://security.netapp.com/advisory/ntap-20190823-0004/https://security.netapp.com/advisory/ntap-20190823-0005/https://security.netapp.com/advisory/ntap-20190823-0001/http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00076.htmlhttps://seclists.org/bugtraq/2019/Aug/43https://www.debian.org/security/2019/dsa-4508http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00021.htmlhttps://access.redhat.com/errata/RHSA-2019:2682https://www.debian.org/security/2019/dsa-4520https://access.redhat.com/errata/RHSA-2019:2726https://seclists.org/bugtraq/2019/Sep/18https://access.redhat.com/errata/RHSA-2019:2594http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlhttps://access.redhat.com/errata/RHSA-2019:2661https://kc.mcafee.com/corporate/index?page=content&id=SB10296https://access.redhat.com/errata/RHSA-2019:2690https://access.redhat.com/errata/RHSA-2019:2766http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00038.htmlhttps://access.redhat.com/errata/RHSA-2019:2796https://access.redhat.com/errata/RHSA-2019:2861https://access.redhat.com/errata/RHSA-2019:2925https://access.redhat.com/errata/RHSA-2019:2939https://access.redhat.com/errata/RHSA-2019:2955https://access.redhat.com/errata/RHSA-2019:2966https://access.redhat.com/errata/RHSA-2019:3131https://access.redhat.com/errata/RHSA-2019:2769https://access.redhat.com/errata/RHSA-2019:3245https://access.redhat.com/errata/RHSA-2019:3265https://access.redhat.com/errata/RHSA-2019:3892https://access.redhat.com/errata/RHSA-2019:3906https://access.redhat.com/errata/RHSA-2019:4018https://access.redhat.com/errata/RHSA-2019:4020https://access.redhat.com/errata/RHSA-2019:4019https://access.redhat.com/errata/RHSA-2019:4021https://access.redhat.com/errata/RHSA-2019:4040https://access.redhat.com/errata/RHSA-2019:4042https://access.redhat.com/errata/RHSA-2019:4041https://access.redhat.com/errata/RHSA-2019:4045https://access.redhat.com/errata/RHSA-2019:4269https://access.redhat.com/errata/RHSA-2019:4273https://access.redhat.com/errata/RHSA-2019:4352https://access.redhat.com/errata/RHSA-2020:0406https://access.redhat.com/errata/RHSA-2020:0727https://usn.ubuntu.com/4308-1/https://www.debian.org/security/2020/dsa-4669https://lists.debian.org/debian-lts-announce/2020/12/msg00011.htmlhttp://www.openwall.com/lists/oss-security/2023/10/18/8https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LYO6E3H34C346D2E443GLXK7OK6KIYIQ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4BBP27PZGSY6OP6D26E5FW4GZKBFHNU7/https://support.f5.com/csp/article/K01988340?utm_source=f5support&%3Butm_medium=RSShttps://nvd.nist.govhttps://usn.ubuntu.com/4308-1/https://www.kb.cert.org/vuls/id/605641