CVE-2019-17569
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
- Affected products
- Apache Tomcat, Suse
- Apache Tomcat
- ≤ 7.0.99, 8.5.50, 9.0.30
- Apache Tomee
- = 7.0.7
- Fix
- Available
- CVSS 2.0
- 5.8 MEDIUM
- CVSS 3.1
- 4.8 MEDIUM
- EPSS
- 8.9% (95th percentile)
- Weakness
- CWE-444
- NVD status
- Modified
- Published
- 2020-02-24
CVE-2019-17569 at NVD
No indexed exploits for CVE-2019-17569 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2019-17569 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.