SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-17567

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass…

MEDIUM 5.3EPSS 60.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 60.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
EPSS
60.27% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
apache/http server · fedoraproject/fedora · oracle/enterprise manager ops center · oracle/instantis enterprisetrack · oracle/zfs storage appliance kit
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.