GHSA-qjwc-v72v-fq6r
Dashboard / Vulnerabilities / GHSA-qjwc-v72v-fq6r
Summary: HTTP request smuggling in Undertow
Details: A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
References: https://nvd.nist.gov/vuln/detail/CVE-2021-20220, https://github.com/undertow-io/undertow/commit/9e797b2f99617fdad0471eaa88c711ee7f44605f, https://bugzilla.redhat.com/show_bug.cgi?id=1923133, https://security.netapp.com/advisory/ntap-20220210-0013
Affected packages
Package
Name: io.undertow:undertow-core
Purl: pkg:maven/io.undertow/undertow-core
Affected ranges
Type: ECOSYSTEM
Events:
