Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qjwc-v72v-fq6r

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

HTTP request smuggling in Undertow

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.6

2.1.6

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.0.34

2.0.34

EPSS

Процентиль: 40%
0.00182
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 4.8
ubuntu
почти 5 лет назад

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 4.8
redhat
около 5 лет назад

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 4.8
nvd
почти 5 лет назад

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 4.8
debian
почти 5 лет назад

A flaw was found in Undertow. A regression in the fix for CVE-2020-106 ...

EPSS

Процентиль: 40%
0.00182
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-444