CVE-2020-27782
published 2021-02-23CVE-2020-27782: A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.27%
66.5th percentile
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.4-1 (forky) | undertow 2.2.4-1 (forky) |
| redhat | jboss_fuse | — | — |
| redhat | jboss_fuse | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.2.4-1 | 2.2.4-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: special character in query results in server errors
vendor_redhat·2021-01-25·CVSS 7.5
CVE-2020-27782 [HIGH] CWE-400 undertow: special character in query results in server errors
undertow: special character in query results in server errors
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability.
Mitigation: The issue can be mitigated by using HTTP/1.1 instead of AJP to proxy to the back-end.
Debian
CVE-2020-27782: undertow - A flaw was found in the Undertow AJP connector. Malicious requests and abrupt co...
vendor_debian·2020·CVSS 7.5
CVE-2020-27782 [HIGH] CVE-2020-27782: undertow - A flaw was found in the Undertow AJP connector. Malicious requests and abrupt co...
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
Scope: local
forky: resolved (fixed in 2.2.4-1)
sid: resolved (fixed in 2.2.4-1)
GHSA
Denial of service in Undertow
ghsa·2022-02-09
CVE-2020-27782 [HIGH] CWE-400 Denial of service in Undertow
Denial of service in Undertow
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
OSV
Denial of service in Undertow
osv·2022-02-09
CVE-2020-27782 [HIGH] Denial of service in Undertow
Denial of service in Undertow
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
OSV
CVE-2020-27782: A flaw was found in the Undertow AJP connector
osv·2021-02-23·CVSS 7.5
CVE-2020-27782 [HIGH] CVE-2020-27782: A flaw was found in the Undertow AJP connector
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-23
Published