Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-12165

Опубликовано: 13 дек. 2017
Источник: redhat
CVSS3: 2.6
EPSS Низкий

Описание

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

It was discovered that Undertow processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7undertowNot affected
Red Hat JBoss Data Grid 7wildfly-undertowNot affected
Red Hat JBoss Fuse 6undertowNot affected
Red Hat Single Sign-On 7wildfly-undertowNot affected
Red Hat Virtualization 4eap7-undertowAffected
Red Hat JBoss A-MQ 6.3FixedRHSA-2018:132203.05.2018
Red Hat JBoss EAP 7FixedRHSA-2017:345613.12.2017
Red Hat JBoss EAP 7undertowFixedRHSA-2018:000303.01.2018
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-activemq-artemisFixedRHSA-2018:000203.01.2018
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-hibernateFixedRHSA-2018:000203.01.2018

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=1490301undertow: improper whitespace parsing leading to potential HTTP request smuggling

EPSS

Процентиль: 78%
0.01096
Низкий

2.6 Low

CVSS3

Связанные уязвимости

CVSS3: 2.6
ubuntu
больше 7 лет назад

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

CVSS3: 2.6
nvd
больше 7 лет назад

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

CVSS3: 2.6
debian
больше 7 лет назад

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 proces ...

CVSS3: 7.5
github
больше 3 лет назад

Undertow Request Smuggling vulnerability

EPSS

Процентиль: 78%
0.01096
Низкий

2.6 Low

CVSS3