Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-12196

Опубликовано: 18 апр. 2018
Источник: nvd
CVSS3: 4.8
CVSS3: 5.9
CVSS2: 4.3
EPSS Низкий

Описание

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
Версия до 1.4.18 (включая)
cpe:2.3:a:redhat:undertow:1.4.24:*:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.2:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:virtualization:4.0:*:*:*:*:*:*:*

EPSS

Процентиль: 44%
0.00214
Низкий

4.8 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287
CWE-863

Связанные уязвимости

CVSS3: 4.8
ubuntu
почти 8 лет назад

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

CVSS3: 4.8
redhat
почти 8 лет назад

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

CVSS3: 4.8
debian
почти 8 лет назад

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was fou ...

CVSS3: 5.9
github
больше 3 лет назад

Incorrect Authorization in Undertow

EPSS

Процентиль: 44%
0.00214
Низкий

4.8 Medium

CVSS3

5.9 Medium

CVSS3

4.3 Medium

CVSS2

Дефекты

CWE-287
CWE-863