CVE-2016-6311
published 2017-08-22CVE-2016-6311: Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
2.26%
81.0th percentile
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
EAP7: Internal IP address disclosed on redirect when request header Host field is not set
vendor_redhat·2016-07-03·CVSS 5.3
CVE-2016-6311 [MEDIUM] CWE-200 EAP7: Internal IP address disclosed on redirect when request header Host field is not set
EAP7: Internal IP address disclosed on redirect when request header Host field is not set
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
It was found that when issuing a GET request which results in a 302 redirect, and when the request header 'Host' field was not set, the response header field 'Location' contains the internal IP address of the server. An attacker could use this disclose information which they are not authorized to access.
Mitigation: You can add a filter in the JBoss CLI that sets the host header to the 'myvirtualhost.com' if the host header is not present. eg:
/subsystem=undertow/configuration=filter/expression-filter=hostname:add(expression="header(header=Host, value=myvirtualhost.com)")
/subsystem=und
GHSA
GHSA-p2j3-7ppx-vcp7: Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers
ghsa_unreviewed·2022-05-17
CVE-2016-6311 [MEDIUM] CWE-200 GHSA-p2j3-7ppx-vcp7: Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers
Get requests in JBoss Enterprise Application Platform (EAP) 7 disclose internal IP addresses to remote attackers.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=1362735https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://bugzilla.redhat.com/show_bug.cgi?id=1362735
2017-08-22
Published