PT-2018-7169 · Red Hat · Undertow
Published
2017-07-11
·
Updated
2021-02-24
·
CVE-2017-2666
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Undertow (affected versions not specified)
Description:
A flaw was found in Undertow where the HTTP request line parsing code allowed invalid characters. This could be exploited, in conjunction with a proxy that also allowed these characters but interpreted them differently, to inject data into the HTTP response. An attacker could manipulate the HTTP response to poison a web-cache, perform a cross-site scripting (XSS) attack, or obtain sensitive information from requests other than their own.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Undertow