Lucene search

K
redhatcveRedhat.comRH:CVE-2020-1935
HistoryFeb 25, 2020 - 6:40 a.m.

CVE-2020-1935

2020-02-2506:40:48
redhat.com
access.redhat.com
25

0.002 Low

EPSS

Percentile

62.3%

A flaw was found in Apache Tomcat. The HTTP header parsing code used an approach to end-of-line (EOL) parsing that allowed some invalid HTTP headers to be parsed as valid. This led to the possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. The highest threat with this vulnerability is system availability.

Mitigation

Workaround for Red Hat Satellite 6 is to add iptables rule to deny TCP requests of Tomcat that are not originating from the Satellite.

For other Red Hat products, either mitigation isn't available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.