CVE-2005-2090

Aliases:GHSA-f2gq-p6qv-ccw4
Advisory lineage Upstream: 0 Downstream: 9
Modified
Published: 30 Jun 2005, 04:00
Last modified:07 Aug 2024, 22:15

Vulnerability Summary

Overall Risk (default)
medium
41/100
CVSS Score
4.3 MEDIUM
v2.0 (nvd)
EPSS Score
71.38% CRITICAL
71% probability -10.61%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

30 Jun 2005, 04:00
Published
Vulnerability first disclosed
07 Aug 2024, 22:15
Last Modified
Vulnerability information updated

Description

Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."

CVSS Metrics

  • v2.0MEDIUMScore: 4.3AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS Trends

Current EPSS score: 71.38% Percentile: 99%

Affected Systems

  • UnknownTomcat

    4.1.24 | 5.0.19

  • org.apache.tomcattomcat

    ≥ 5.0.0, ≤ 5.0.19 | ≥ 4.0.0, ≤ 4.1.24

References (59)