CVE-2019-17569
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression.
Does this matter?
Lower severity and a low EPSS score (8.87%). Track it; it rarely justifies an emergency change on its own.
Description
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
- CVSS 3.1
- 4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 8.87% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-444
- Affected
- apache/tomcat · apache/tomee · opensuse/leap · netapp/data availability services · netapp/oncommand system manager · debian/debian linux · oracle/agile engineering data management · oracle/agile product lifecycle management · oracle/communications instant messaging server · oracle/health sciences empirica inspections · oracle/health sciences empirica signal · oracle/hospitality guest access · oracle/instantis enterprisetrack · oracle/mysql enterprise monitor · oracle/transportation management · oracle/workload manager
- Source
- security@apache.org
References
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.htmlMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3EMailing List, Vendor Advisory
- https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/03/msg00006.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200327-0005/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4673Third Party Advisory
- https://www.debian.org/security/2020/dsa-4680Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.htmlMailing List, Third Party Advisory
- https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
- https://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3EMailing List, Vendor Advisory
- https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E
- https://lists.debian.org/debian-lts-announce/2020/03/msg00006.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200327-0005/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4673Third Party Advisory
- https://www.debian.org/security/2020/dsa-4680Third Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.htmlPatch, Third Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.htmlPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.