CVE-2021-20220

Description

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

Risk Information

Base Score
4.8
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.182

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2021-20220 are fixed in Undertow-core 2.1.6Windows
Vulnerabilities CVE-2021-20220 are fixed in Undertow-core 2.0.34Windows
Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3Windows
Multiple Vulnerabilities are affected in Netapp Oncommand Workflow Automation 2.3Windows
Vulnerabilities CVE-2021-20220 are fixed in Undertow-core for Linux 2.1.6Linux
Vulnerabilities CVE-2021-20220 are fixed in Undertow-core for Linux 2.0.34Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234