[MAVEN:GHSA-5GG7-5WV8-4GCJ] Undertow Request Smuggling vulnerability

Severity High
Affected Packages 3
Fixed Packages 3
CVEs 1

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

ID
MAVEN:GHSA-5GG7-5WV8-4GCJ
Severity
high
URL
https://github.com/advisories/GHSA-5gg7-5wv8-4gcj
Published
2022-05-13T01:38:14
(2 years ago)
Modified
2023-01-29T05:03:44
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.undertow/undertow-core io.undertow undertow-core = 2.0.0.Alpha1
Fixed pkg:maven/io.undertow/undertow-core io.undertow undertow-core = 2.0.0.Beta1
Affected pkg:maven/io.undertow/undertow-core io.undertow undertow-core >= 1.4.0 < 1.4.17
Fixed pkg:maven/io.undertow/undertow-core io.undertow undertow-core = 1.4.17
Affected pkg:maven/io.undertow/undertow-core io.undertow undertow-core < 1.3.31
Fixed pkg:maven/io.undertow/undertow-core io.undertow undertow-core = 1.3.31
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...