Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2021-06-10T07:10:19

Updated: 2024-08-05T01:40:15.824Z

Reserved: 2019-10-14T00:00:00

Link: CVE-2019-17567

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-06-10T07:15:07.200

Modified: 2024-06-10T17:16:08.460

Link: CVE-2019-17567

cve-icon Redhat

Severity : Moderate

Publid Date: 2021-06-04T00:00:00Z

Links: CVE-2019-17567 - Bugzilla