CVE-2020-1710
published 2020-09-16CVE-2020-1710: The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
PriorityP424medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
1.19%
64.4th percentile
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | jboss_data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
EAP: field-name is not parsed in accordance to RFC7230
vendor_redhat·2020-08-06·CVSS 5.3
CVE-2020-1710 [MEDIUM] CWE-74 EAP: field-name is not parsed in accordance to RFC7230
EAP: field-name is not parsed in accordance to RFC7230
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
A flaw was discovered in JBoss EAP, where it does not process the header field-name in accordance with RFC7230. Whitespace between the header field-name and colon is processed, resulting in an HTTP response code of 200 instead of a bad request of 400.
Mitigation: There is currently no known mitigation for this issue.
Package: undertow (Red Hat Decision Manager 7) - Not affected
Package: jbossweb (Red Hat JBoss Data Virtualization 6) - Out of support scope
Package: jbossweb (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: tomcat (Red Hat JBoss Web Server 3)
GHSA
GHSA-xqwp-g97m-cxpr: The issue appears to be that JBoss EAP 6
ghsa_unreviewed·2022-05-24
CVE-2020-1710 [MEDIUM] GHSA-xqwp-g97m-cxpr: The issue appears to be that JBoss EAP 6
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-2109 jenkins-pipeline-groovy-plugin: sandbox protection bypass through default parameter expressions in CPS-transformed methods
bugzilla·2020-03-31·CVSS 8.8
CVE-2020-2109 [HIGH] CVE-2020-2109 jenkins-pipeline-groovy-plugin: sandbox protection bypass through default parameter expressions in CPS-transformed methods
CVE-2020-2109 jenkins-pipeline-groovy-plugin: sandbox protection bypass through default parameter expressions in CPS-transformed methods
A vulnerability was found in Jenkins Pipeline: Groovy Plugin 2.78 and earlier, where sandbox protection can be circumvented through default parameter expressions in CPS-transformed methods.
Reference:
http://www.openwall.com/lists/oss-security/2020/02/12/3
Discussion:
External References:
https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1710
---
This issue has been addressed in the following products:
Red Hat OpenShift Container Platform 3.11
Via RHSA-2020:2478 https://access.redhat.com/errata/RHSA-2020:2478
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.
Bugzilla
CVE-2020-1710 EAP: field-name is not parsed in accordance to RFC7230
bugzilla·2020-01-22·CVSS 5.3
CVE-2020-1710 [MEDIUM] CVE-2020-1710 EAP: field-name is not parsed in accordance to RFC7230
CVE-2020-1710 EAP: field-name is not parsed in accordance to RFC7230
The issue appears to be that EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2020:3464 https://access.redhat.com/errata/RHSA-2020:3464
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 6
Via RHSA-2020:3461 https://access.redhat.com/errata/RHSA-2020:3461
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.3 for RHEL 7
Via RHSA-2020:3462 https://access.redhat.com/errata/RHSA-2020:3462
---
This issue has b
2020-09-16
Published