Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p9w3-gwc2-cr49

Опубликовано: 30 апр. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

HTTP Request Smuggling in Undertow

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

<= 2.1.0.Final

2.2.0.Final

EPSS

Процентиль: 32%
0.00123
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 5 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

CVSS3: 4.8
redhat
почти 6 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

CVSS3: 4.8
nvd
больше 5 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

CVSS3: 4.8
debian
больше 5 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2. ...

EPSS

Процентиль: 32%
0.00123
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-444