Description
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- apache / Apache Tomcat8.5.48 to 8.5.50 – 8.5.48 to 8.5.50
- apache / Apache Tomcat7.0.98 to 7.0.99 – 7.0.98 to 7.0.99
- apache / Apache TomcatApache Tomcat 9.0.28 to 9.0.30 – Apache Tomcat 9.0.28 to 9.0.30
- apache / Tomcat7.0.98 – 7.0.99
- apache / tomee7.0.7 – 7.0.7
- debian / debian_linux10.0 – 10.0
- debian / debian_linux9.0 – 9.0
- NETAPP / data_availability_services
- NETAPP / oncommand_system_manager3.0.0 – 3.1.3
- openSUSE / Leap15.1 – 15.1
- oracle / agile_engineering_data_management6.2.1.0 – 6.2.1.0
- oracle / agile_product_lifecycle_management9.3.3 – 9.3.3
- oracle / agile_product_lifecycle_management9.3.5 – 9.3.5
- oracle / agile_product_lifecycle_management9.3.6 – 9.3.6
- oracle / communications_instant_messaging_server10.0.1.4.0 – 10.0.1.4.0
- oracle / health_sciences_empirica_inspections1.0.1.2 – 1.0.1.2
- oracle / health_sciences_empirica_signal7.3.3 – 7.3.3
- oracle / hospitality_guest_access4.2.0 – 4.2.0
- oracle / hospitality_guest_access4.2.1 – 4.2.1
- oracle / instantis_enterprisetrack17.1 – 17.3
- oracle / MySQL Enterprise Monitor4.0.12
- oracle / transportation_management6.3.7 – 6.3.7
- oracle / workload_manager12.2.0.1 – 12.2.0.1
- oracle / workload_manager18c – 18c
- oracle / workload_manager19c – 19c
References
- MAILING_LISThttps://lists.apache.org/thread.html/r88def002c5c78534674ca67472e035099fbe088813d50062094a1390%40%3Cannounce.tomcat.apache.org%3E
- MAILING_LISThttps://lists.debian.org/debian-lts-announce/2020/03/msg00006.html
- MAILING_LISThttp://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html
- MAILING_LISThttps://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E
- MAILING_LISThttps://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4673
- VENDOR_ADVISORYhttps://www.debian.org/security/2020/dsa-4680
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujul2020.html
- MISChttps://security.netapp.com/advisory/ntap-20200327-0005/
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpuoct2020.html
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2021.html
Updated 20m ago · 8 sources