PT-2018-8406 · Red Hat · Undertow
Publicado
2018-01-10
·
Atualizado
2022-05-13
·
CVE-2017-7559
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Undertow versions 1.3.x before 1.3.31.Final
Undertow versions 1.4.x before 1.4.17.Final
Undertow versions 2.x before 2.0.0.Alpha2
Description
The issue allows invalid characters in the query string and path parameters. This could be exploited to inject data into the HTTP response, potentially leading to web-cache poisoning, XSS attacks, or obtaining sensitive information from other requests.
Recommendations
For Undertow versions 1.3.x before 1.3.31.Final, update to version 1.3.31.Final or later.
For Undertow versions 1.4.x before 1.4.17.Final, update to version 1.4.17.Final or later.
For Undertow versions 2.x before 2.0.0.Alpha2, update to version 2.0.0.Alpha2 or later.
Correção
HTTP Request/Response Smuggling
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Undertow