BIT-tomcat-2020-1935

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/tomcat/BIT-tomcat-2020-1935.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-tomcat-2020-1935
Aliases
Published
2024-03-06T11:11:33.381Z
Modified
2024-03-06T11:25:28.861Z
Summary
[none]
Details

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

References

Affected packages

Bitnami / tomcat

Package

Name
tomcat
Purl
pkg:bitnami/tomcat

Severity

  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
7.0.0
Fixed
7.0.99
Introduced
8.5.0
Fixed
8.5.50
Introduced
9.0.0
Fixed
9.0.30
Type
SEMVER
Events
Introduced
9.0.0
Last affected
9.0.0
Introduced
9.0.0-milestone1
Last affected
9.0.0-milestone1
Introduced
9.0.0-milestone10
Last affected
9.0.0-milestone10
Introduced
9.0.0-milestone11
Last affected
9.0.0-milestone11
Introduced
9.0.0-milestone12
Last affected
9.0.0-milestone12
Introduced
9.0.0-milestone13
Last affected
9.0.0-milestone13
Introduced
9.0.0-milestone14
Last affected
9.0.0-milestone14
Introduced
9.0.0-milestone15
Last affected
9.0.0-milestone15
Introduced
9.0.0-milestone16
Last affected
9.0.0-milestone16
Introduced
9.0.0-milestone17
Last affected
9.0.0-milestone17
Introduced
9.0.0-milestone18
Last affected
9.0.0-milestone18
Introduced
9.0.0-milestone19
Last affected
9.0.0-milestone19
Introduced
9.0.0-milestone2
Last affected
9.0.0-milestone2
Introduced
9.0.0-milestone20
Last affected
9.0.0-milestone20
Introduced
9.0.0-milestone21
Last affected
9.0.0-milestone21
Introduced
9.0.0-milestone22
Last affected
9.0.0-milestone22
Introduced
9.0.0-milestone23
Last affected
9.0.0-milestone23
Introduced
9.0.0-milestone24
Last affected
9.0.0-milestone24
Introduced
9.0.0-milestone25
Last affected
9.0.0-milestone25
Introduced
9.0.0-milestone26
Last affected
9.0.0-milestone26
Introduced
9.0.0-milestone27
Last affected
9.0.0-milestone27
Introduced
9.0.0-milestone3
Last affected
9.0.0-milestone3
Introduced
9.0.0-milestone4
Last affected
9.0.0-milestone4
Introduced
9.0.0-milestone5
Last affected
9.0.0-milestone5
Introduced
9.0.0-milestone6
Last affected
9.0.0-milestone6
Introduced
9.0.0-milestone7
Last affected
9.0.0-milestone7
Introduced
9.0.0-milestone8
Last affected
9.0.0-milestone8
Introduced
9.0.0-milestone9
Last affected
9.0.0-milestone9