CVE-2017-12196
published 2018-04-18CVE-2017-12196: undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value…
PriorityP335medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
2.05%
79.2th percentile
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 1.4.25-1 (forky) | undertow 1.4.25-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | undertow | <= 1.4.18 | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 1.4.25-1 | 1.4.25-1 |
| redhat | virtualization | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.9MEDIUM
vendor_debian4.8MEDIUM
vendor_redhat4.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Incorrect Authorization in Undertow
osv·2022-05-13
CVE-2017-12196 [MEDIUM] Incorrect Authorization in Undertow
Incorrect Authorization in Undertow
Undertow before versions 1.4.18.SP1 (not findable in Maven), 2.0.2.Final, and 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
GHSA
Incorrect Authorization in Undertow
ghsa·2022-05-13
CVE-2017-12196 [MEDIUM] CWE-863 Incorrect Authorization in Undertow
Incorrect Authorization in Undertow
Undertow before versions 1.4.18.SP1 (not findable in Maven), 2.0.2.Final, and 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
OSV
CVE-2017-12196: undertow before versions 1
osv·2018-04-18·CVSS 5.9
CVE-2017-12196 [MEDIUM] CVE-2017-12196: undertow before versions 1
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
Red Hat
undertow: Client can use bogus uri in Digest authentication
vendor_redhat·2018-03-12·CVSS 4.8
CVE-2017-12196 [MEDIUM] CWE-287 undertow: Client can use bogus uri in Digest authentication
undertow: Client can use bogus uri in Digest authentication
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
It was discovered that when using Digest authentication, the server does not ensure that the value of the URI in the authorization header matches the URI in the HTTP request line. This allows the attacker to execute a MITM attack and access the desired content on the server.
Package: camel (Red Hat JBoss Fuse 6) - Will not fix
Package: undertow (Red Hat JBoss Fuse Integration Service 2) - Affected
Package
Debian
CVE-2017-12196: undertow - undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnera...
vendor_debian·2017·CVSS 4.8
CVE-2017-12196 [MEDIUM] CVE-2017-12196: undertow - undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnera...
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
Scope: local
forky: resolved (fixed in 1.4.25-1)
sid: resolved (fixed in 1.4.25-1)
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://access.redhat.com/errata/RHSA-2018:1525https://access.redhat.com/errata/RHSA-2018:2405https://access.redhat.com/errata/RHSA-2018:3768https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12196https://issues.jboss.org/browse/UNDERTOW-1190https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://access.redhat.com/errata/RHSA-2018:1525https://access.redhat.com/errata/RHSA-2018:2405https://access.redhat.com/errata/RHSA-2018:3768https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12196https://issues.jboss.org/browse/UNDERTOW-1190
2018-04-18
Published