Lucene search

K
osvGoogleOSV:CVE-2019-17567
HistoryJun 10, 2021 - 7:15 a.m.

CVE-2019-17567

2021-06-1007:15:07
Google
osv.dev
11
apache http server
mod_proxy_wstunnel
security bypass

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

68.5%

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

References