SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid.

MEDIUM 4.8EPSS 9.39%

Does this matter?

Lower severity and a low EPSS score (9.39%). Track it; it rarely justifies an emergency change on its own.

Description

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS 3.1
4.8 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS
9.39% probability · 95th percentile
CISA KEV
Not listed
Weakness
CWE-444
Affected
apache/tomcat · debian/debian linux · canonical/ubuntu linux · opensuse/leap · netapp/data availability services · netapp/oncommand system manager · oracle/agile engineering data management · oracle/agile product lifecycle management · oracle/communications element manager · oracle/communications instant messaging server · oracle/health sciences empirica inspections · oracle/health sciences empirica signal · oracle/hospitality guest access · oracle/hyperion infrastructure technology · oracle/instantis enterprisetrack · oracle/mysql enterprise monitor · oracle/retail order broker · oracle/siebel ui framework · oracle/transportation management · oracle/workload manager
Source
security@apache.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.