CVE-2018-1067
published 2018-05-21CVE-2018-1067: In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the…
PriorityP431medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.76%
75.4th percentile
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 1.4.25-1 (forky) | undertow 1.4.25-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 1.4.25 | 1.4.25 |
| redhat | undertow | >= 0 < 1.4.25-1 | 1.4.25-1 |
| redhat | undertow | >= 2.0.0 < 2.0.5 | 2.0.5 |
| redhat | virtualization_host | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.1MEDIUM
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
vendor_redhat·2018-04-25·CVSS 6.1
CVE-2018-1067 [MEDIUM] CWE-113 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
It was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Package: tomcat5 (Red Hat Enterprise Linux 5) - Not affected
Package: t
Debian
CVE-2018-1067: undertow - In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CV...
vendor_debian·2018·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067: undertow - In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CV...
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Scope: local
forky: resolved (fixed in 1.4.25-1)
sid: resolved (fixed in 1.4.25-1)
OSV
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
osv·2022-05-13·CVSS 6.1
CVE-2018-1067 [MEDIUM] Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
GHSA
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
ghsa·2022-05-13·CVSS 6.1
CVE-2018-1067 [MEDIUM] CWE-113 Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
Improper Neutralization of CRLF Sequences in HTTP Headers in Undertow
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
OSV
CVE-2018-1067: In Undertow before versions 7
osv·2018-05-21·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067: In Undertow before versions 7
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1067 tomcat: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
bugzilla·2018-06-19·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 tomcat: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
CVE-2018-1067 tomcat: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Bugzilla
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
bugzilla·2018-06-19·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE:
Bugzilla
CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
bugzilla·2018-06-19·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
CVE-2018-1067 wildfly: undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993) [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message
Bugzilla
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
bugzilla·2018-03-01·CVSS 6.1
CVE-2018-1067 [MEDIUM] CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
A flaw was reported in WildFly 12.0.0.CR1 web server is vulnerable to the injection of arbitrary HTTP Header due to insufficient sanitisation and validation of user UTF-8 encoded input before it is used as part of an HTTP header value.
Although there is a protection against CRLF injection by detecting the presence of a NewLine character (0x0a), it can be bypassed using characters encoded in UTF-8 as the page will try to convert them back to the original Unicode form and extract the last byte.
Discussion:
Acknowledgments:
Name: Ammarit Thongthua (Deloitte Thailand Pentest team), Nattakit Intarasorn (Deloitte Thailand Pentest team)
---
This issue has been addressed in the fol
https://access.redhat.com/errata/RHSA-2018:1247https://access.redhat.com/errata/RHSA-2018:1248https://access.redhat.com/errata/RHSA-2018:1249https://access.redhat.com/errata/RHSA-2018:1251https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2019:0877https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1067https://access.redhat.com/errata/RHSA-2018:1247https://access.redhat.com/errata/RHSA-2018:1248https://access.redhat.com/errata/RHSA-2018:1249https://access.redhat.com/errata/RHSA-2018:1251https://access.redhat.com/errata/RHSA-2018:2643https://access.redhat.com/errata/RHSA-2019:0877https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-1067
2018-05-21
Published