CVE-2017-12165
published 2018-07-27CVE-2017-12165: It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request…
PriorityP338high7.5CVSS 3.0
AVNACLPRNUINSUCNIHAN
EPSS
1.86%
76.7th percentile
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.0.23-1 (forky) | undertow 2.0.23-1 (forky) |
| red_hat | undertow | — | — |
| red_hat | undertow | — | — |
| red_hat | undertow | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.0.23-1 | 2.0.23-1 |
| redhat | undertow | >= 1.0.0 < 1.3.31 | 1.3.31 |
| redhat | undertow | >= 1.4.0 < 1.4.17 | 1.4.17 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
osv7.5HIGH
vendor_debian2.6LOW
vendor_redhat2.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: improper whitespace parsing leading to potential HTTP request smuggling
vendor_redhat·2017-12-13·CVSS 2.6
CVE-2017-12165 [LOW] CWE-444 undertow: improper whitespace parsing leading to potential HTTP request smuggling
undertow: improper whitespace parsing leading to potential HTTP request smuggling
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
It was discovered that Undertow processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Package: undertow (Red Hat Fuse 7) - Not affected
Package: wildfly-undertow (Red Hat JBoss Data Grid 7) - Not affected
Package: undertow (Red Hat JBoss Fuse 6) - Not affected
Package: wildfly-undertow (Red Hat Single Sign-On 7) - Not affected
Package: eap7-undertow (Red Hat Virtualization 4) - Affected
Debian
CVE-2017-12165: undertow - It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http r...
vendor_debian·2017·CVSS 2.6
CVE-2017-12165 [LOW] CVE-2017-12165: undertow - It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http r...
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Scope: local
forky: resolved (fixed in 2.0.23-1)
sid: resolved (fixed in 2.0.23-1)
OSV
Undertow Request Smuggling vulnerability
osv·2022-05-13
CVE-2017-12165 [HIGH] Undertow Request Smuggling vulnerability
Undertow Request Smuggling vulnerability
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
GHSA
Undertow Request Smuggling vulnerability
ghsa·2022-05-13
CVE-2017-12165 [HIGH] CWE-444 Undertow Request Smuggling vulnerability
Undertow Request Smuggling vulnerability
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
OSV
CVE-2017-12165: It was discovered that Undertow before 1
osv·2018-07-27·CVSS 7.5
CVE-2017-12165 [HIGH] CVE-2017-12165: It was discovered that Undertow before 1
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-12165 undertow: improper whitespace parsing leading to potential HTTP request smuggling
bugzilla·2017-09-11·CVSS 2.6
CVE-2017-12165 [LOW] CVE-2017-12165 undertow: improper whitespace parsing leading to potential HTTP request smuggling
CVE-2017-12165 undertow: improper whitespace parsing leading to potential HTTP request smuggling
It was discovered that Undertow processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Discussion:
Acknowledgments:
Name: Stuart Douglas (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
Via RHSA-2017:3454 https://access.redhat.com/errata/RHSA-2017:3454
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
Via R
Bugzilla
CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
bugzilla·2017-08-15·CVSS 6.5
CVE-2017-7559 [MEDIUM] CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
It was found that original patch for CVE-2017-2666 issue in undertow was incomplete and invalid characters are still allowed in the query string and path parameters.
Discussion:
Acknowledgments:
Name: Stuart Douglas (Red Hat)
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
Via RHSA-2017:3454 https://access.redhat.com/errata/RHSA-2017:3454
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Pla
https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://access.redhat.com/errata/RHSA-2018:0002https://access.redhat.com/errata/RHSA-2018:0003https://access.redhat.com/errata/RHSA-2018:0004https://access.redhat.com/errata/RHSA-2018:0005https://access.redhat.com/errata/RHSA-2018:1322https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12165https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://access.redhat.com/errata/RHSA-2018:0002https://access.redhat.com/errata/RHSA-2018:0003https://access.redhat.com/errata/RHSA-2018:0004https://access.redhat.com/errata/RHSA-2018:0005https://access.redhat.com/errata/RHSA-2018:1322https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12165
2018-07-27
Published