CVE-2017-7559
published 2018-01-10CVE-2017-7559: In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and…
PriorityP427medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.65%
73.9th percentile
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 1.4.23-1 (forky) | undertow 1.4.23-1 (forky) |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 1.4.23-1 | 1.4.23-1 |
| redhat | undertow | >= 1.3.0 < 1.3.31 | 1.3.31 |
| redhat | undertow | >= 1.4.0 < 1.4.17 | 1.4.17 |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
vendor_redhat·2017-12-13·CVSS 6.5
CVE-2017-7559 [MEDIUM] CWE-444 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
It was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This
Debian
CVE-2017-7559: undertow - In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before...
vendor_debian·2017·CVSS 6.5
CVE-2017-7559 [MEDIUM] CVE-2017-7559: undertow - In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before...
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Scope: local
forky: resolved (fixed in 1.4.23-1)
sid: resolved (fixed in 1.4.23-1)
GHSA
Undertow vulnerable to Request Smuggling
ghsa·2022-05-13·CVSS 6.5
CVE-2017-7559 [MEDIUM] CWE-444 Undertow vulnerable to Request Smuggling
Undertow vulnerable to Request Smuggling
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
OSV
Undertow vulnerable to Request Smuggling
osv·2022-05-13·CVSS 6.5
CVE-2017-7559 [MEDIUM] Undertow vulnerable to Request Smuggling
Undertow vulnerable to Request Smuggling
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
OSV
CVE-2017-7559: In Undertow 2
osv·2018-01-10·CVSS 6.5
CVE-2017-7559 [MEDIUM] CVE-2017-7559: In Undertow 2
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://access.redhat.com/errata/RHSA-2018:0002https://access.redhat.com/errata/RHSA-2018:0003https://access.redhat.com/errata/RHSA-2018:0004https://access.redhat.com/errata/RHSA-2018:0005https://access.redhat.com/errata/RHSA-2018:1322https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7559https://issues.jboss.org/browse/UNDERTOW-1251https://access.redhat.com/errata/RHSA-2017:3454https://access.redhat.com/errata/RHSA-2017:3455https://access.redhat.com/errata/RHSA-2017:3456https://access.redhat.com/errata/RHSA-2017:3458https://access.redhat.com/errata/RHSA-2018:0002https://access.redhat.com/errata/RHSA-2018:0003https://access.redhat.com/errata/RHSA-2018:0004https://access.redhat.com/errata/RHSA-2018:0005https://access.redhat.com/errata/RHSA-2018:1322https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7559https://issues.jboss.org/browse/UNDERTOW-1251
2018-01-10
Published