CVE-2019-17567 Details
Description
Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
A vulnerability exists in Apache HTTP Server in versions 2.4.6 to 2.4.46, specifically within the mod_proxy_wstunnel module. When configured on a URL that is not guaranteed to be upgraded by the origin server, the module improperly tunnels the entire connection. This misconfiguration allows subsequent requests on the same connection to bypass HTTP validation, authentication, and authorization, potentially leading to unauthorized access or actions.
Users are advised to upgrade to Apache HTTP Server version 2.4.48 or later, where this vulnerability has been fixed. For those using package managers, instructions can be found in the update notifications for the respective distribution.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-444 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache http server | >= 2.4.6, <= 2.4.46 |
CPE
Remediation
| |
| fedoraproject fedora | 34 35 |
CPE
Remediation
| |
| oracle enterprise manager ops center | 12.4.0.0 |
CPE
Remediation
| |
| oracle instantis enterprisetrack | 17.1 17.2 17.3 |
CPE
Remediation
| |
| oracle zfs storage appliance kit | 8.8 |
CPE
Remediation
| |
Change History
15 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 10, 2024 | CVE Modified | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Dec 2, 2021 | Modified Analysis | [email protected] |
| Oct 20, 2021 | CVE Modified | [email protected] |
| Sep 25, 2021 | CVE Modified | [email protected] |
| Sep 21, 2021 | Modified Analysis | [email protected] |
| Sep 20, 2021 | CVE Modified | [email protected] |
| Jul 17, 2021 | CVE Modified | [email protected] |
| Jul 2, 2021 | CVE Modified | [email protected] |
| Jun 16, 2021 | Initial Analysis | [email protected] |
| Jun 10, 2021 | CVE Modified | [email protected] |
| Jun 10, 2021 | CVE Modified | [email protected] |