Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-12196

Опубликовано: 18 апр. 2018
Источник: ubuntu
Приоритет: medium
CVSS2: 4.3
CVSS3: 4.8

Описание

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needed
cosmic

not-affected

1.4.25-1
devel

not-affected

2.3.8-2
disco

not-affected

1.4.25-1
eoan

not-affected

1.4.25-1
esm-apps/bionic

needed

esm-apps/focal

not-affected

1.4.25-1
esm-apps/jammy

not-affected

1.4.25-1
esm-apps/noble

needs-triage

Показывать по

4.3 Medium

CVSS2

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
redhat
почти 8 лет назад

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

CVSS3: 4.8
nvd
почти 8 лет назад

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

CVSS3: 4.8
debian
почти 8 лет назад

undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was fou ...

CVSS3: 5.9
github
больше 3 лет назад

Incorrect Authorization in Undertow

4.3 Medium

CVSS2

4.8 Medium

CVSS3