CVE-2019-17569

Source
https://cve.org/CVERecord?id=CVE-2019-17569
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17569.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-17569
Aliases
Downstream
Related
Published
2020-02-24T22:15:11.903Z
Modified
2026-02-11T07:29:28.489423Z
Severity
  • 4.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

References

Affected packages

Git
github.com/apache/tomcat

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17569.json"
github.com/apache/tomee

Affected ranges

Type
GIT
Repo
https://github.com/apache/tomee
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

tomee-7.*
tomee-7.0.5
tomee-7.0.6
tomee-7.0.7

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17569.json"
github.com/imagemagick/imagemagick

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

7.*
7.0.1-0
7.0.1-1
7.0.1-10
7.0.1-2
7.0.1-3
7.0.1-4
7.0.1-5
7.0.1-6
7.0.1-7
7.0.1-8
7.0.1-9
7.0.2-0
7.0.2-1
7.0.2-10
7.0.2-2
7.0.2-3
7.0.2-4
7.0.2-5
7.0.2-6
7.0.2-7
7.0.2-8
7.0.2-9
7.0.3-0
7.0.3-1
7.0.3-10
7.0.3-2
7.0.3-3
7.0.3-4
7.0.3-5
7.0.3-6
7.0.3-7
7.0.3-8
7.0.3-9
7.0.4-0
7.0.4-1
7.0.4-10
7.0.4-2
7.0.4-3
7.0.4-4
7.0.4-5
7.0.4-6
7.0.4-7
7.0.4-8
7.0.4-9
7.0.5-0
7.0.5-1
7.0.5-10
7.0.5-2
7.0.5-3
7.0.5-4
7.0.5-5
7.0.5-6
7.0.5-7
7.0.5-8
7.0.5-9
7.0.6-0
7.0.6-1
7.0.6-2
7.0.6-3
7.0.6-4
7.0.6-5
7.0.6-6
7.0.6-7
7.0.6-8
7.0.6-9
7.0.7-0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-17569.json"