PT-2018-8406 · Red Hat · Undertow

Publicado

2018-01-10

·

Atualizado

2022-05-13

·

CVE-2017-7559

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Undertow versions 1.3.x before 1.3.31.Final Undertow versions 1.4.x before 1.4.17.Final Undertow versions 2.x before 2.0.0.Alpha2
Description The issue allows invalid characters in the query string and path parameters. This could be exploited to inject data into the HTTP response, potentially leading to web-cache poisoning, XSS attacks, or obtaining sensitive information from other requests.
Recommendations For Undertow versions 1.3.x before 1.3.31.Final, update to version 1.3.31.Final or later. For Undertow versions 1.4.x before 1.4.17.Final, update to version 1.4.17.Final or later. For Undertow versions 2.x before 2.0.0.Alpha2, update to version 2.0.0.Alpha2 or later.

Correção

HTTP Request/Response Smuggling

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-7559
GHSA-RJ76-H87P-R3WF
RHSA-2017:3454
RHSA-2017:3455
RHSA-2017:3458
RHSA-2018:0002
RHSA-2018:0004
RHSA-2018:0005

Produtos afetados

Undertow