Логотип exploitDog
bind:"CVE-2020-1935"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2020-1935"

Количество 13

Количество 13

ubuntu логотип

CVE-2020-1935

больше 5 лет назад

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS3: 4.8
EPSS: Низкий
redhat логотип

CVE-2020-1935

больше 5 лет назад

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-1935

больше 5 лет назад

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS3: 4.8
EPSS: Низкий
debian логотип

CVE-2020-1935

больше 5 лет назад

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0. ...

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-qxf4-chvg-4r8r

больше 5 лет назад

Potential HTTP request smuggling in Apache Tomcat

CVSS3: 4.8
EPSS: Низкий
oracle-oval логотип

ELSA-2020-5020

больше 4 лет назад

ELSA-2020-5020: tomcat security update (LOW)

EPSS: Низкий
fstec логотип

BDU:2020-03567

больше 5 лет назад

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 4.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:2611-1

почти 5 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2020:0345-1

больше 5 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0631-1

больше 5 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0598-1

больше 5 лет назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2020:0632-1

больше 5 лет назад

Security update for tomcat

EPSS: Низкий
rocky логотип

RLSA-2020:4847

больше 4 лет назад

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
redhat логотип
CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-1935

In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0. ...

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
github логотип
GHSA-qxf4-chvg-4r8r

Potential HTTP request smuggling in Apache Tomcat

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
oracle-oval логотип
ELSA-2020-5020

ELSA-2020-5020: tomcat security update (LOW)

больше 4 лет назад
fstec логотип
BDU:2020-03567

Уязвимость сервера приложений Apache Tomcat, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

CVSS3: 4.8
1%
Низкий
больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:2611-1

Security update for tomcat

почти 5 лет назад
suse-cvrf логотип
openSUSE-SU-2020:0345-1

Security update for tomcat

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0631-1

Security update for tomcat

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0598-1

Security update for tomcat

больше 5 лет назад
suse-cvrf логотип
SUSE-SU-2020:0632-1

Security update for tomcat

больше 5 лет назад
rocky логотип
RLSA-2020:4847

Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update

больше 4 лет назад

Уязвимостей на страницу