Redhat Undertow vulnerabilities
45 known vulnerabilities affecting redhat/undertow.
Total CVEs
45
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH24MEDIUM17
Vulnerabilities
Page 3 of 3
CVE-2017-7559P4MEDIUMCVSS 6.1≥ 1.3.0, < 1.3.31≥ 1.4.0, < 1.4.17+1 more2018-01-10
CVE-2017-7559 [MEDIUM] CVE-2017-7559: In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it wa
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpre
nvdosv
CVE-2016-7046P4MEDIUMCVSS 5.9≥ 0, < 1.4.3-12016-10-03
CVE-2016-7046 [MEDIUM] CVE-2016-7046: Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a
Red Hat JBoss Enterprise Application Platform (EAP) 7, when operating as a reverse-proxy with default buffer sizes, allows remote attackers to cause a denial of service (CPU and disk consumption) via a long URL.
osv
CVE-2021-20220P4MEDIUMCVSS 4.8fixed in 2.0.34≥ 2.1.0, < 2.1.62021-02-23
CVE-2021-20220 [MEDIUM] CVE-2021-20220: A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smu
A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than
nvdosv
CVE-2020-10687P4MEDIUMCVSS 4.8fixed in 2.2.02020-09-23
CVE-2020-10687 [MEDIUM] CVE-2020-10687: A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request sm
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other tha
nvdosv
CVE-2022-2764P4MEDIUMCVSS 4.9≥ 2.0.0, ≤ 2.2.19v2.3.0+1 more2022-09-01
CVE-2022-2764 [MEDIUM] CWE-400 CVE-2022-2764: A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAS
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
nvdosv
← Previous3 / 3