Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 11 min 115 bronnen 1 kritiek 13 vandaag
CVE's Videos Dagbriefing

← Terug naar CVE-database

CVE-2021-33037

MEDIUM · 5.3 CVSS Gepubliceerd: CWE-444

Beschrijving

Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.

Vendors

Apache Debian Oracle Mcafee

Affected products

Tomcat Tomee Debian Linux Agile Product Lifecycle Management Communications Cloud Native Core Policy Communications Cloud Native Core Service Communication Proxy Communications Diameter Signaling Router Communications Instant Messaging Server Communications Policy Management Communications Pricing Design Center Communications Session Report Manager Communications Session Route Manager Graph Server And Client Healthcare Translational Research Hospitality Cruise Shipboard Property Management System Instantis Enterprisetrack Managed File Transfer Mysql Enterprise Monitor Sd-wan Edge Secure Global Desktop Utilities Testing Accelerator Epolicy Orchestrator

References