Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcqr-hcjq-whfq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Improper Neutralization of CRLF Sequences in Wildfly Undertow

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Пакеты

Наименование

org.wildfly:wildfly-undertow

maven
Затронутые версииВерсия исправления

>= 10.0.0.Final, <= 10.1.0.Final

11.0.0.Final

EPSS

Процентиль: 84%
0.0256
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 6.1
ubuntu
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 5.4
redhat
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
nvd
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
debian
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10. ...

EPSS

Процентиль: 84%
0.0256
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-93