Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-10687

Опубликовано: 15 апр. 2020
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

A flaw was discovered in Undertow where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Continuous Deliverywildfly-undertowOut of support scope
Red Hat JBoss Fuse 6wildfly-undertowOut of support scope
Red Hat Fuse 7.7.0FixedRHSA-2020:319228.07.2020
Red Hat JBoss Enterprise Application Platform 7wildfly-undertowFixedRHSA-2020:364207.09.2020
Red Hat JBoss Enterprise Application Platform 7FixedRHSA-2021:088516.03.2021
Red Hat JBoss Enterprise Application Platform 7wildfly-undertowFixedRHSA-2020:346417.08.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-dom4jFixedRHSA-2020:363707.09.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-elytron-webFixedRHSA-2020:363707.09.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-glassfish-jsfFixedRHSA-2020:363707.09.2020
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-hal-consoleFixedRHSA-2020:363707.09.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=1785049Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests

EPSS

Процентиль: 32%
0.00123
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 5 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

CVSS3: 4.8
nvd
больше 5 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.

CVSS3: 4.8
debian
больше 5 лет назад

A flaw was discovered in all versions of Undertow before Undertow 2.2. ...

CVSS3: 4.8
github
почти 5 лет назад

HTTP Request Smuggling in Undertow

EPSS

Процентиль: 32%
0.00123
Низкий

4.8 Medium

CVSS3