Уязвимость CVE-2020-1935: Информация

Описание

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

Важность: MEDIUM (4,8) Вектор: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Опубликовано: 25 февраля 2020 г.
Изменено: 7 ноября 2023 г.
Идентификатор типа ошибки: CWE-444

Исправленные пакеты

Имя пакета
Ветка
Исправлено в версии
Версия в репозитории
Errata ID
№ Задания
Состояние
tomcatsisyphus9.0.37-alt19.0.83-alt1_1jpp11ALT-PU-2020-2892-1255548Исправлено
tomcatp109.0.37-alt19.0.59-alt1_3jpp11ALT-PU-2020-2892-1255548Исправлено
tomcatp99.0.37-alt19.0.37-alt1ALT-PU-2020-3213-2258915Исправлено
tomcatc10f19.0.37-alt19.0.59-alt1_3jpp11ALT-PU-2020-2892-1255548Исправлено
tomcatc9f29.0.37-alt0.c9.19.0.37-alt0.c9.1ALT-PU-2021-2858-2282600Исправлено
tomcatp119.0.37-alt19.0.83-alt1_1jpp11ALT-PU-2020-2892-1255548Исправлено

Ссылки на рекомендации, решения и инструменты

    1. Конфигурация 1

      cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*

      cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
      Start including
      7.0.0
      End including
      7.0.99

      cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
      Start including
      8.5.0
      End including
      8.5.50

      cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
      Start including
      9.0.0
      End including
      9.0.30

      cpe:2.3:a:apache:tomcat:9.0.0:-:*:*:*:*:*:*

      Конфигурация 2

      cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

      cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*

      Конфигурация 3

      cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

      Конфигурация 4

      cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*

      Конфигурация 5

      cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*
      Start including
      3.0.0
      End including
      3.1.3

      cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*

      Конфигурация 6

      cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.5:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:*
      Start including
      17.1
      End including
      17.3

      cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:hyperion_infrastructure_technology:11.1.2.4:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
      Start including
      8.0.0
      End including
      8.0.20

      cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*
      End including
      20.5

      cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.2:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
      Start including
      4.0.0
      End including
      4.0.12