GHSA-p9w3-gwc2-cr49
Dashboard / Vulnerabilities / GHSA-p9w3-gwc2-cr49
Summary: HTTP Request Smuggling in Undertow
Details: A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-10687, https://bugzilla.redhat.com/show_bug.cgi?id=1785049, https://lists.apache.org/thread.html/r6603513ea8afbf6857fd77ca5888ec8385d0af493baa4250e28c351c@%3Cdev.cxf.apache.org%3E, https://security.netapp.com/advisory/ntap-20220210-0015
Affected packages
Package
Name: io.undertow:undertow-core
Purl: pkg:maven/io.undertow/undertow-core
Affected ranges
Type: ECOSYSTEM
Events:
