CVE-2017-2666
Last modified
CVE-2017-2666 is a vulnerability of currently unknown severity. It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. EPSS estimates a 2.71% chance of exploitation in the next 30 days.
Description
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Undertow | All versions |
| Redhat | Jboss Enterprise Application Platform | 7.0.0 |
| Redhat | Jboss Enterprise Application Platform | 7.1.0 |
| Debian | Debian Linux | 9.0 |
| Debian | Debian Linux | 10.0 |
References
- http://rhn.redhat.com/errata/RHSA-2017-1409.htmlVendor Advisory
- http://www.securityfocus.com/bid/98966Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1410Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1411Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1412Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3454Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3455Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3456Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3458Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2666Issue Tracking, Vendor Advisory
- https://www.debian.org/security/2017/dsa-3906Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2017-1409.htmlVendor Advisory
- http://www.securityfocus.com/bid/98966Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1410Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1411Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:1412Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3454Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3455Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3456Vendor Advisory
- https://access.redhat.com/errata/RHSA-2017:3458Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2666Issue Tracking, Vendor Advisory
- https://www.debian.org/security/2017/dsa-3906Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-2666?
How severe is CVE-2017-2666?
How do I fix CVE-2017-2666?
Are you affected by CVE-2017-2666?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
