ZeroHour

CVE-2017-12165

CVSS 3.0
7.5 high
EPSS
2%p78
Published
()
Modified
Description

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Vendors
redhat
Products
undertow, jboss enterprise application platform
Weakness
CWE-444
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.