Sploitus

CVE-2020-1935

No indexed exploits for CVE-2020-1935 yet

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

Apache Tomcat
≤ 7.0.99, 8.5.50, 9.0.30, 9.0.0
Fix
Available
CVSS 2.0
5.8 MEDIUM
CVSS 3.1
4.8 MEDIUM
EPSS
9.4% (95th percentile)
Weakness
CWE-444
NVD status
Modified
Published
2020-02-24
CVE-2020-1935 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2020-1935 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2020-1935 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.