CVE-2016-4993
published 2016-09-26CVE-2016-4993: CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2…
PriorityP428medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
2.56%
83.3th percentile
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 1.4.25-1 (forky) | undertow 1.4.25-1 (forky) |
| debian | undertow | < undertow 1.4.3-1 (forky) | undertow 1.4.3-1 (forky) |
| redhat | jboss_enterprise_application_platform | <= 7.0.1 | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_wildfly_application_server | — | — |
| redhat | undertow | < 1.4.25 | 1.4.25 |
| redhat | undertow | >= 0 < 1.4.3-1 | 1.4.3-1 |
| redhat | undertow | >= 0 < 1.4.25-1 | 1.4.25-1 |
| redhat | undertow | >= 2.0.0 < 2.0.5 | 2.0.5 |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
vendor_redhat·2018-04-25·CVSS 6.1
CVE-2018-1067 [MEDIUM] CWE-113 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
It was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Package: tomcat5 (Red Hat Enterprise Linux 5) - Not affected
Package: t
Debian
CVE-2018-1067: undertow - In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CV...
vendor_debian·2018·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067: undertow - In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CV...
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Scope: local
forky: resolved (fixed in 1.4.25-1)
sid: resolved (fixed in 1.4.25-1)
Red Hat
eap: HTTP header injection / response splitting
vendor_redhat·2016-09-08·CVSS 6.1
CVE-2016-4993 [MEDIUM] CWE-113 eap: HTTP header injection / response splitting
eap: HTTP header injection / response splitting
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
It was reported that EAP 7 Application Server/Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: jbossweb (Red Hat JBoss Enterprise Application Platform 6) - N
Debian
CVE-2016-4993: undertow - CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as us...
vendor_debian·2016·CVSS 6.1
CVE-2016-4993 [MEDIUM] CVE-2016-4993: undertow - CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as us...
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Scope: local
forky: resolved (fixed in 1.4.3-1)
sid: resolved (fixed in 1.4.3-1)
OSV
Improper Neutralization of CRLF Sequences in Wildfly Undertow
osv·2022-05-17
CVE-2016-4993 [MEDIUM] Improper Neutralization of CRLF Sequences in Wildfly Undertow
Improper Neutralization of CRLF Sequences in Wildfly Undertow
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
GHSA
Improper Neutralization of CRLF Sequences in Wildfly Undertow
ghsa·2022-05-17
CVE-2016-4993 [MEDIUM] CWE-93 Improper Neutralization of CRLF Sequences in Wildfly Undertow
Improper Neutralization of CRLF Sequences in Wildfly Undertow
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
OSV
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
osv·2022-05-13·CVSS 6.1
CVE-2018-1067 [MEDIUM] Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
GHSA
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
ghsa·2022-05-13·CVSS 6.1
CVE-2018-1067 [MEDIUM] CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
OSV
CVE-2018-1067: In Undertow before versions 7
osv·2018-05-21·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067: In Undertow before versions 7
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
OSV
CVE-2016-4993: CRLF injection vulnerability in the Undertow web server in WildFly 10
osv·2016-09-26·CVSS 6.1
CVE-2016-4993 [MEDIUM] CVE-2016-4993: CRLF injection vulnerability in the Undertow web server in WildFly 10
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1067 tomcat: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
bugzilla·2018-06-19·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 tomcat: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
CVE-2018-1067 tomcat: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
bugzilla·2018-06-19·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
bugzilla·2018-06-19·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
bugzilla·2018-03-01·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
A flaw was reported in WildFly 12.0.0.CR1 web server is vulnerable to the injection of arbitrary HTTP Header due to insufficient sanitisation and validation of user UTF-8 encoded input before it is used as part of an HTTP header value.
Although there is a protection against CRLF injection by detecting the presence of a NewLine character (0x0a), it can be bypassed using characters encoded in UTF-8 as the page will try to convert them back to the original Unicode form and extract the last byte.
Discussion:
Acknowledgments:
Name: Ammarit Thongthua (Deloitte Thailand Pentest team), Nattakit Intarasorn (Deloitte Thailand Pentest team)
---
This issue has been addressed in the fol
Bugzilla
CVE-2016-4993 eap: HTTP header injection / response splitting
bugzilla·2016-06-09·CVSS 6.1
CVE-2016-4993 [MEDIUM] CVE-2016-4993 eap: HTTP header injection / response splitting
CVE-2016-4993 eap: HTTP header injection / response splitting
It was reported that WildFly 10.0.0 Application Server/Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also Response Splitting, due to insufficient sanitisation and validation of user input before the input is used as part of a HTTP header value.
Using newline characters injected into the HTTP headers, it is possible for the malicious user to add arbitrary headers such as Set-Cookie to set arbitrary cookies, or potentially use a Location header for an open-redirect. By using two newline characters the attacker can 'split' the response (HTTP Response Splitting) and provide their own content that will be rendered to the victim user.
Discussion:
Acknowledgments:
Name: Calum Hutton (NCC Group),
http://rhn.redhat.com/errata/RHSA-2016-1838.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1839.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1840.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1841.htmlhttp://www.securityfocus.com/bid/92894http://www.securitytracker.com/id/1036758https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=1344321http://rhn.redhat.com/errata/RHSA-2016-1838.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1839.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1840.htmlhttp://rhn.redhat.com/errata/RHSA-2016-1841.htmlhttp://www.securityfocus.com/bid/92894http://www.securitytracker.com/id/1036758https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=1344321
2016-09-26
Published