PT-2018-7169 · Red Hat · Undertow

Published

2017-07-11

·

Updated

2021-02-24

·

CVE-2017-2666

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Undertow (affected versions not specified)
Description: A flaw was found in Undertow where the HTTP request line parsing code allowed invalid characters. This could be exploited, in conjunction with a proxy that also allowed these characters but interpreted them differently, to inject data into the HTTP response. An attacker could manipulate the HTTP response to poison a web-cache, perform a cross-site scripting (XSS) attack, or obtain sensitive information from requests other than their own.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-2666
DSA-3906-1
GHSA-MCFM-H73V-635M
RHSA-2017:1410
RHSA-2017:1411
RHSA-2017:1412
RHSA-2017:3454
RHSA-2017:3455
RHSA-2017:3458

Affected Products

Undertow