CVE-2021-20220
published 2021-02-23CVE-2021-20220: A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against…
PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
1.12%
62.5th percentile
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.2.0-1 (forky) | undertow 2.2.0-1 (forky) |
| redhat | undertow | < 2.0.34 | 2.0.34 |
| redhat | undertow | >= 0 < 2.2.0-1 | 2.2.0-1 |
| redhat | undertow | >= 2.1.0 < 2.1.6 | 2.1.6 |
CVSS provenance
nvdv3.14.8MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa6.5MEDIUM
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: Possible regression in fix for CVE-2020-10687
vendor_redhat·2021-02-04·CVSS 6.5
CVE-2021-20220 [MEDIUM] CWE-444 undertow: Possible regression in fix for CVE-2020-10687
undertow: Possible regression in fix for CVE-2020-10687
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perfo
Debian
CVE-2021-20220: undertow - A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was fou...
vendor_debian·2021·CVSS 6.5
CVE-2021-20220 [MEDIUM] CVE-2021-20220: undertow - A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was fou...
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
Scope: local
forky: resolved (fixed in 2.2.0-1)
sid: resolved (fixed in 2.2.0-1)
OSV
HTTP request smuggling in Undertow
osv·2021-06-16·CVSS 6.5
CVE-2021-20220 [MEDIUM] HTTP request smuggling in Undertow
HTTP request smuggling in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
GHSA
HTTP request smuggling in Undertow
ghsa·2021-06-16·CVSS 6.5
CVE-2021-20220 [MEDIUM] CWE-444 HTTP request smuggling in Undertow
HTTP request smuggling in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
OSV
CVE-2021-20220: A flaw was found in Undertow
osv·2021-02-23·CVSS 6.5
CVE-2021-20220 [MEDIUM] CVE-2021-20220: A flaw was found in Undertow
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.
No detection rules found.
No public exploits indexed.
2021-02-23
Published