CVE-2019-17567: Apache HTTP Server

Medium severity, CVSS 5.3. EPSS: 60.3% chance of exploitation in the next 30 days.

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.

Affected products

  • Apache HTTP Server: from 2.4.6, up to and including 2.4.46
  • Fedoraproject Fedora: version 34 only; version 35 only
  • Oracle Enterprise Manager Ops Center: version 12.4.0.0 only
  • Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
  • Oracle ZFS Storage Appliance Kit: version 8.8 only

Published 2021-06-10. Last modified 2026-06-17.