694
VMScore

CVE-2019-9515

Published: 13/08/2019 Updated: 07/11/2023
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 694
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

it exists that Twisted incorrectly validated or sanitized certain URIs or HTTP methods. A remote attacker could use this issue to inject invalid characters and possibly perform header injection attacks. (CVE-2019-12387)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

apple swiftnio

apache traffic server

canonical ubuntu linux 16.04

canonical ubuntu linux 18.04

canonical ubuntu linux 19.04

debian debian linux 9.0

debian debian linux 10.0

synology skynas -

synology diskstation manager 6.2

synology vs960hd_firmware -

fedoraproject fedora 29

fedoraproject fedora 30

opensuse leap 15.0

opensuse leap 15.1

redhat software collections 1.0

redhat jboss core services 1.0

redhat enterprise linux 8.0

redhat jboss enterprise application platform 7.2.0

redhat single sign-on 7.3

redhat openshift container platform 4.1

redhat quay 3.0.0

redhat openshift service mesh 1.0

redhat openstack 14

redhat jboss enterprise application platform 7.3.0

oracle graalvm 19.2.0

mcafee web gateway

f5 big-ip local traffic manager

nodejs node.js

Vendor Advisories

Several security issues were fixed in Twisted ...
Debian Bug report logs - #934886 CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 Package: src:h2o; Maintainer for src:h2o is Apollon Oikonomopoulos <apoikos@debianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 16 Aug 2019 08:06:02 UTC Severity: grave Tags: security, upstream Forwarded to git ...
Debian Bug report logs - #934887 CVE-2019-9512 CVE-2019-9514 CVE-2019-9515 Package: src:trafficserver; Maintainer for src:trafficserver is Jean Baptiste Favre <debian@jbfavreorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 16 Aug 2019 08:06:06 UTC Severity: grave Tags: security, upstream Found in v ...
Three vulnerabilities were discovered in the HTTP/2 code of the H2O HTTP server, which could result in denial of service For the stable distribution (buster), these problems have been fixed in version 225+dfsg2-2+deb10u1 We recommend that you upgrade your h2o packages For the detailed security status of h2o please refer to its security tracker ...
Several vulnerabilities were discovered in the HTTP/2 code of Apache Traffic Server, a reverse and forward proxy server, which could result in denial of service The fixes are too intrusive to backport to the version in the oldstable distribution (stretch) An upgrade to Debian stable (buster) is recommended instead For the stable distribution (bu ...
Impact: Important Public Date: 2019-08-13 CWE: CWE-400 Bugzilla: 1735745: CVE-2019-9515 istio/envoy: HT ...
Synopsis Important: Red Hat Single Sign-On 735 security update on RHEL 6 Type/Severity Security Advisory: Important Topic New Red Hat Single Sign-On 735 packages are now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72Red Hat Product Security has rated this update as having a security impact of Important A ...
Synopsis Important: Red Hat Process Automation Manager 780 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Process Automation ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scori ...
Synopsis Important: Red Hat Decision Manager 780 Security Update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat Decision ManagerRed Hat Product Security has rated this update as having a security impact of Moderate A Common Vulnerability Scoring System (CVSS) bas ...
Synopsis Important: Red Hat OpenShift Enterprise 4115 gRPC security update Type/Severity Security Advisory: Important Topic An update for gRPC, included in multus-cni-container, operator-lifecycle-manager-container, and operator-registry-container is now available for Red Hat OpenShift Container Platform ...
Synopsis Important: rh-nodejs10-nodejs security update Type/Severity Security Advisory: Important Topic An update for rh-nodejs10-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring S ...
Synopsis Important: rh-nodejs8-nodejs security update Type/Severity Security Advisory: Important Topic An update for rh-nodejs8-nodejs is now available for Red Hat Software CollectionsRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring Sys ...
Synopsis Important: Red Hat Single Sign-On 735 security update Type/Severity Security Advisory: Important Topic A security update is now available for Red Hat Single Sign-On 73 from the Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulne ...
Synopsis Important: Red Hat Single Sign-On 735 security update on RHEL 7 Type/Severity Security Advisory: Important Topic New Red Hat Single Sign-On 735 packages are now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: OpenShift Container Platform 4118 gRPC security update Type/Severity Security Advisory: Important Topic An update for gRPC, included in sriov-network-device-plugin-container, is now available for Red Hat OpenShift Container Platform 41Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat Data Grid 733 security update Type/Severity Security Advisory: Important Topic An update for Red Hat Data Grid is now availableRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, whic ...
Synopsis Important: Red Hat Single Sign-On 735 security update on RHEL 8 Type/Severity Security Advisory: Important Topic New Red Hat Single Sign-On 735 packages are now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Co ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 on RHEL 7 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72 for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat Fuse 750 security update Type/Severity Security Advisory: Important Topic A minor version update (from 74 to 75) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Synopsis Important: Red Hat Fuse 760 security update Type/Severity Security Advisory: Important Topic A minor version update (from 75 to 76) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 on RHEL 8 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72 for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as ...
Synopsis Important: Red Hat JBoss Enterprise Application Platform 725 on RHEL 6 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Enterprise Application Platform 72 for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as ...
Synopsis Important: EAP Continuous Delivery Technical Preview Release 18 security update Type/Severity Security Advisory: Important Topic This is a security update for JBoss EAP Continuous Delivery 180Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnera ...
Synopsis Important: Red Hat AMQ Broker 76 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 76 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Sco ...
Synopsis Important: nodejs:10 security update Type/Severity Security Advisory: Important Topic An update for the nodejs:10 module is now available for Red Hat Enterprise Linux 8Red Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CV ...
Synopsis Important: Red Hat JBoss Fuse/A-MQ 63 R14 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Fuse 63 and Red Hat JBoss A-MQ 63Red Hat Product Security has rated this update as having a security impact of Important A Common ...
Synopsis Important: Red Hat AMQ Broker 743 release and security update Type/Severity Security Advisory: Important Topic Red Hat AMQ Broker 743 is now available from the Red Hat Customer PortalRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability ...
Synopsis Important: Red Hat build of Thorntail 251 security and bug fix update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat build of ThorntailRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> APPLE-SA-2019-08-13-5 SwiftNIO HTTP/2 150 <!--X-Subject-Header-End--> <!--X-Head-of-Message--> From: Apple Product ...

References

CWE-770https://kb.cert.org/vuls/id/605641/https://github.com/Netflix/security-bulletins/blob/master/advisories/third-party/2019-002.mdhttps://seclists.org/bugtraq/2019/Aug/24http://seclists.org/fulldisclosure/2019/Aug/16https://www.synology.com/security/advisory/Synology_SA_19_33https://support.f5.com/csp/article/K50233772https://security.netapp.com/advisory/ntap-20190823-0005/https://seclists.org/bugtraq/2019/Aug/43https://www.debian.org/security/2019/dsa-4508https://www.debian.org/security/2019/dsa-4520https://seclists.org/bugtraq/2019/Sep/18http://lists.opensuse.org/opensuse-security-announce/2019-09/msg00032.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-09/msg00031.htmlhttps://kc.mcafee.com/corporate/index?page=content&id=SB10296https://access.redhat.com/errata/RHSA-2019:2766https://access.redhat.com/errata/RHSA-2019:2796https://access.redhat.com/errata/RHSA-2019:2861https://access.redhat.com/errata/RHSA-2019:2925https://access.redhat.com/errata/RHSA-2019:2939https://access.redhat.com/errata/RHSA-2019:2955https://access.redhat.com/errata/RHSA-2019:3892https://access.redhat.com/errata/RHSA-2019:4018https://access.redhat.com/errata/RHSA-2019:4019https://access.redhat.com/errata/RHSA-2019:4021https://access.redhat.com/errata/RHSA-2019:4020https://access.redhat.com/errata/RHSA-2019:4041https://access.redhat.com/errata/RHSA-2019:4040https://access.redhat.com/errata/RHSA-2019:4042https://access.redhat.com/errata/RHSA-2019:4045https://access.redhat.com/errata/RHSA-2019:4352https://access.redhat.com/errata/RHSA-2020:0727https://usn.ubuntu.com/4308-1/https://lists.apache.org/thread.html/bde52309316ae798186d783a5e29f4ad1527f61c9219a289d0eee0a7%40%3Cdev.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/392108390cef48af647a2e47b7fd5380e050e35ae8d1aa2030254c04%40%3Cusers.trafficserver.apache.org%3Ehttps://lists.apache.org/thread.html/ad3d01e767199c1aed8033bb6b3f5bf98c011c7c536f07a5d34b3c19%40%3Cannounce.trafficserver.apache.org%3Ehttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CMNFX5MNYRWWIMO4BTKYQCGUDMHO3AXP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4ZQGHE3WTYLYAYJEIDJVF2FIGQTAYPMC/https://support.f5.com/csp/article/K50233772?utm_source=f5support&%3Butm_medium=RSShttps://nvd.nist.govhttps://usn.ubuntu.com/4308-1/https://www.kb.cert.org/vuls/id/605641