Описание
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
Отчет
This vulnerability has an Important severity because it can be remotely exploited without authentication. However, limited user interaction is required for full impact. It could allow attackers to hijack additional accounts, steal credentials, or gain access to internal systems. The issue stems from improper input validation of HTTP Host headers, leading to serious breaches in confidentiality and integrity.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use, applicability, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | undertow-core | Not affected | ||
| Red Hat Data Grid 8 | undertow-core | Will not fix | ||
| Red Hat Enterprise Linux 10 | moditect | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 9 | resteasy | Not affected | ||
| Red Hat Fuse 7 | undertow-core | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow-core | Affected | ||
| Red Hat Process Automation 7 | undertow-core | Will not fix | ||
| Red Hat Single Sign-On 7 | undertow-core | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
9.6 Critical
CVSS3
Связанные уязвимости
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling attackers to poison caches, perform internal network scans, or hijack user sessions.
A flaw was found in the Undertow HTTP server core, which is used in Wi ...
Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests
Уязвимость ядра HTTP-сервера Undertow, связанная с ошибками механизма проверки входных данных при обработке заголовков Host, позволяющая нарушителю осуществить SSRF-атаку
EPSS
9.6 Critical
CVSS3