CVE-2020-10687
published 2021-02-23CVE-2020-10687: A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against…
PriorityP423medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
1.15%
63.2th percentile
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.0-1 (forky) | undertow 2.2.0-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | < 2.0.34 | 2.0.34 |
| redhat | undertow | < 2.2.0 | 2.2.0 |
| redhat | undertow | >= 0 < 2.2.0-1 | 2.2.0-1 |
| redhat | undertow | >= 2.1.0 < 2.1.6 | 2.1.6 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: Possible regression in fix for CVE-2020-10687
vendor_redhat·2021-02-04·CVSS 6.5
CVE-2021-20220 [MEDIUM] CWE-444 undertow: Possible regression in fix for CVE-2020-10687
undertow: Possible regression in fix for CVE-2020-10687
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perfo
Debian
CVE-2021-20220: undertow - A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was fou...
vendor_debian·2021·CVSS 6.5
CVE-2021-20220 [MEDIUM] CVE-2021-20220: undertow - A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was fou...
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
Red Hat
Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
vendor_redhat·2020-04-15·CVSS 6.5
CVE-2020-10687 [MEDIUM] CWE-444 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
A flaw was discovered in Undertow where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
P
Debian
CVE-2020-10687: undertow - A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, w...
vendor_debian·2020·CVSS 6.5
CVE-2020-10687 [MEDIUM] CVE-2020-10687: undertow - A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, w...
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
Scope: local
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
OSV
HTTP request smuggling in Undertow
osv·2021-06-16·CVSS 6.5
CVE-2021-20220 [MEDIUM] HTTP request smuggling in Undertow
HTTP request smuggling in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
GHSA
HTTP request smuggling in Undertow
ghsa·2021-06-16·CVSS 6.5
CVE-2021-20220 [MEDIUM] CWE-444 HTTP request smuggling in Undertow
HTTP request smuggling in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
HTTP Request Smuggling in Undertow
osv·2021-04-30·CVSS 6.5
CVE-2020-10687 [MEDIUM] HTTP Request Smuggling in Undertow
HTTP Request Smuggling in Undertow
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
GHSA
HTTP Request Smuggling in Undertow
ghsa·2021-04-30·CVSS 6.5
CVE-2020-10687 [MEDIUM] CWE-444 HTTP Request Smuggling in Undertow
HTTP Request Smuggling in Undertow
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
OSV
CVE-2021-20220: A flaw was found in Undertow
osv·2021-02-23·CVSS 6.5
CVE-2021-20220 [MEDIUM] CVE-2021-20220: A flaw was found in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
CVE-2020-10687: A flaw was discovered in all versions of Undertow before Undertow 2
osv·2020-09-23·CVSS 6.5
CVE-2020-10687 [MEDIUM] CVE-2020-10687: A flaw was discovered in all versions of Undertow before Undertow 2
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2021-20220 undertow: Possible regression in fix for CVE-2020-10687
bugzilla·2021-02-01·CVSS 4.8
CVE-2021-20220 [MEDIUM] CVE-2021-20220 undertow: Possible regression in fix for CVE-2020-10687
CVE-2021-20220 undertow: Possible regression in fix for CVE-2020-10687
A regression issue reintroduced undertow's CVE-2020-10687 after undertow 2.0.30.SP4.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2021:0885 https://access.redhat.com/errata/RHSA-2021:0885
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7
Via RHSA-2021:0873 https://access.redhat.com/errata/RHSA-2021:0873
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 8
Via RHSA-2021:0874 https://access.redhat.com/errata/RHSA-2021:0874
---
This issue has been addressed in the following products:
Red Hat
Bugzilla
CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
bugzilla·2019-12-19·CVSS 6.5
CVE-2020-10687 [MEDIUM] CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
CVE-2020-10687 Undertow: Incomplete fix for CVE-2017-2666 due to permitting invalid characters in HTTP requests
A flaw was found in Undertow where HTTP request smuggling related to CVE-2017-2666 might still be possible against HTTP/2.
Discussion:
Acknowledgments:
Name: Aaron Ogburn (Red Hat)
---
This vulnerability is out of security support scope for the following products:
* Red Hat JBoss Fuse 6
Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details.
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2020:3464 https://access.redhat.com/errata/RHSA-2020:3464
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RH
2021-02-23
Published