PT-2021-13850 · Netapp+10 · Active Iq Unified Manager+3

Pedro Sampaio

·

Published

2021-02-23

·

Updated

2022-02-22

·

CVE-2021-20220

CVSS v3.1

4.8

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-20220
GHSA-QJWC-V72V-FQ6R
RHSA-2021:0872
RHSA-2021:0873
RHSA-2021:0874

Affected Products

Active Iq Unified Manager
Io.Undertow:Undertow-Core
Oncommand Workflow Automation
Undertow