CVE-2017-12165HTTP Request Smuggling in Redhat Undertow

Severity
7.5HIGHNVD
CNA2.6
EPSS
1.1%
top 21.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 27
Latest updateMay 13

Description

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDredhat/undertow1.0.01.3.31+2
Debianredhat/undertow< 2.0.23-1
CVEListV5red_hat/undertow1.3.31, 1.4.17, 2.0.0+2

🔴Vulnerability Details

4
OSV
Undertow Request Smuggling vulnerability2022-05-13
GHSA
Undertow Request Smuggling vulnerability2022-05-13
CVEList
CVE-2017-12165: It was discovered that Undertow before 12018-07-27
OSV
CVE-2017-12165: It was discovered that Undertow before 12018-07-27

📋Vendor Advisories

2
Red Hat
undertow: improper whitespace parsing leading to potential HTTP request smuggling2017-12-13
Debian
CVE-2017-12165: undertow - It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http r...2017

💬Community

1
Bugzilla
CVE-2017-12165 undertow: improper whitespace parsing leading to potential HTTP request smuggling2017-09-11
CVE-2017-12165 — HTTP Request Smuggling in Redhat | cvebase