CVE-2019-17567

mod_proxy_wstunnel tunneling of non Upgraded connections

Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent requests on the same connection to pass through with no HTTP validation, authentication or authorization possibly configured.


We have discovered 950,818 live websites that are affected by CVE-2019-17567.

Run a Free Instant Scan




Affected Software

Product  Apache
Category Web Servers
Vulnerable Domains950,818 live websites (34% of Apache install base)
Vulnerable Versions
  • from 2.4.6 through 2.4.6
  • from 2.4.7 through 2.4.7
  • from 2.4.9 through 2.4.9
  • from 2.4.10 through 2.4.10
  • from 2.4.12 through 2.4.12
  • from 2.4.16 through 2.4.16
  • from 2.4.17 through 2.4.17
  • from 2.4.18 through 2.4.18
  • from 2.4.20 through 2.4.20
  • from 2.4.23 through 2.4.23
  • from 2.4.25 through 2.4.25
  • from 2.4.26 through 2.4.26
  • from 2.4.27 through 2.4.27
  • from 2.4.28 through 2.4.28
  • from 2.4.29 through 2.4.29
  • from 2.4.33 through 2.4.33
  • from 2.4.34 through 2.4.34
  • from 2.4.35 through 2.4.35
  • from 2.4.37 through 2.4.37
  • from 2.4.38 through 2.4.38
  • from 2.4.39 through 2.4.39
  • from 2.4.41 through 2.4.41
  • from 2.4.43 through 2.4.43
  • from 2.4.46 through 2.4.46
Vulnerable Versions Count24 versions ( 20% of all versions)



Details

  • Published - Jun 10, 2021
  • Updated - Aug 5, 2024

Credits

  • Reported by Mikhail Egorov (<0ang3el gmail.com>)

Website Distribution by Country

Number of websites using CVE-2019-17567
United States290,809 websites



Germany90,028 websites
France58,414 websites
Japan42,252 websites
Russia38,101 websites
Italy34,686 websites
Netherlands33,719 websites
Singapore28,624 websites
Czech Republic27,436 websites
Canada25,674 websites

Website Distribution by TLD

Number of websites using CVE-2019-17567
.com362,387 websites
.de55,136 websites
.org43,093 websites
.net37,160 websites
.ru33,156 websites
.it31,391 websites
.nl24,808 websites
.cz22,728 websites
.pl20,707 websites
.fr18,729 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2019-17567

Top websites that are affected by CVE-2019-17567. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.com Singapore***
*************.***.****.****.************.net United States***
*********.net United States***
***.****.us United States*,***
***.*********.com Singapore*,***
*****.*******.com Singapore*,***
******************.com United States*,***
****.*********.net GB*,***
*******.org United States*,***
****.com United States*,***
See full domain list

FAQ

A total of 950,818 websites have been identified as vulnerable to CVE-2019-17567, based on global website indexing conducted by WebTechSurvey.
The Apache is affected by the CVE-2019-17567 vulnerability.
Apache versions up to and including 2.4.46 are vulnerable to CVE-2019-17567.

References