Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qcqr-hcjq-whfq

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Improper Neutralization of CRLF Sequences in Wildfly Undertow

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Пакеты

Наименование

org.wildfly:wildfly-undertow

maven
Затронутые версииВерсия исправления

>= 10.0.0.Final, <= 10.1.0.Final

11.0.0.Final

EPSS

Процентиль: 81%
0.01476
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-93

Связанные уязвимости

CVSS3: 6.1
ubuntu
больше 9 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 5.4
redhat
больше 9 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
nvd
больше 9 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
debian
больше 9 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10. ...

EPSS

Процентиль: 81%
0.01476
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-93