Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cccf-7xw3-p2vr

Опубликовано: 30 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

HTTP Request Smuggling in Undertow

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

<= 2.1.0.Final

2.1.1.Final

EPSS

Процентиль: 38%
0.00167
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
redhat
почти 6 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
nvd
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.

CVSS3: 6.5
debian
больше 5 лет назад

A flaw was found in Undertow in versions before 2.1.1.Final, regarding ...

EPSS

Процентиль: 38%
0.00167
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-444