CVE-2017-12165

Description

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
1.096

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2017-12165,CVE-2017-2666 are fixed in Undertow-core 1.3.31Windows
Vulnerabilities CVE-2017-12165,CVE-2017-2666 are fixed in Undertow-core 1.4.17Windows
Vulnerabilities CVE-2017-12165 are fixed in Undertow-core 2.0.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.0.0Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.1.0Windows
Vulnerabilities CVE-2017-12165,CVE-2017-2666 are fixed in Undertow-core for Linux 1.3.31Linux
Vulnerabilities CVE-2017-12165,CVE-2017-2666 are fixed in Undertow-core for Linux 1.4.17Linux
Vulnerabilities CVE-2017-12165 are fixed in Undertow-core for Linux 2.0.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234