← Volver a CVEs
CVE-2017-2666
N/ADescripcion
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado7/27/2018
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0
Productos afectados
debian:debian_linuxredhat:enterprise_linuxredhat:jboss_enterprise_application_platformredhat:undertow
Debilidades (CWE)
CWE-444CWE-444
Referencias
http://rhn.redhat.com/errata/RHSA-2017-1409.html(secalert@redhat.com)
http://www.securityfocus.com/bid/98966(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:1410(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:1411(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:1412(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:3454(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:3455(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:3456(secalert@redhat.com)
https://access.redhat.com/errata/RHSA-2017:3458(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2666(secalert@redhat.com)
https://www.debian.org/security/2017/dsa-3906(secalert@redhat.com)
http://rhn.redhat.com/errata/RHSA-2017-1409.html(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/98966(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:1410(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:1411(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:1412(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:3454(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:3455(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:3456(af854a3a-2127-422b-91ae-364da2661108)
https://access.redhat.com/errata/RHSA-2017:3458(af854a3a-2127-422b-91ae-364da2661108)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-2666(af854a3a-2127-422b-91ae-364da2661108)
https://www.debian.org/security/2017/dsa-3906(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.