[MAVEN:GHSA-CP7V-VMV7-6X2Q] Incorrect Authorization in Undertow

Severity Moderate
Affected Packages 2
Fixed Packages 2
CVEs 1

Undertow before versions 1.4.18.SP1 (not findable in Maven), 2.0.2.Final, and 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

Package Affected Version
pkg:maven/io.undertow/undertow-core <= 1.4.23.Final
pkg:maven/io.undertow/undertow-core >= 2.0.0.Alpha1, <= 2.0.1.Final
Package Fixed Version
pkg:maven/io.undertow/undertow-core = 1.4.24.Final
pkg:maven/io.undertow/undertow-core = 2.0.2.FInal
ID
MAVEN:GHSA-CP7V-VMV7-6X2Q
Severity
moderate
URL
https://github.com/advisories/GHSA-cp7v-vmv7-6x2q
Published
2022-05-13T01:38:10
(2 years ago)
Modified
2023-01-27T05:02:16
(20 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/io.undertow/undertow-core io.undertow undertow-core <= 1.4.23.Final
Fixed pkg:maven/io.undertow/undertow-core io.undertow undertow-core = 1.4.24.Final
Affected pkg:maven/io.undertow/undertow-core io.undertow undertow-core >= 2.0.0.Alpha1 <= 2.0.1.Final
Fixed pkg:maven/io.undertow/undertow-core io.undertow undertow-core = 2.0.2.FInal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...