Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2016-4993

Опубликовано: 26 сент. 2016
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 4.3
CVSS3: 6.1

Описание

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

РелизСтатусПримечание
bionic

not-affected

1.4.23-3
devel

not-affected

2.3.8-2
esm-apps-legacy/xenial

needed

esm-apps/bionic

not-affected

1.4.23-3
esm-apps/focal

not-affected

esm-apps/jammy

not-affected

esm-apps/noble

needs-triage

esm-apps/resolute

not-affected

2.3.8-2
esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

Показывать по

EPSS

Процентиль: 84%
0.0256
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
redhat
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
nvd
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

CVSS3: 6.1
debian
почти 10 лет назад

CRLF injection vulnerability in the Undertow web server in WildFly 10. ...

CVSS3: 6.1
github
больше 4 лет назад

Improper Neutralization of CRLF Sequences in Wildfly Undertow

EPSS

Процентиль: 84%
0.0256
Низкий

4.3 Medium

CVSS2

6.1 Medium

CVSS3

Уязвимость CVE-2016-4993