Back to search
CVE-2020-10687
Published: Sep 23, 2020
Modified: Aug 4, 2024
PUBLISHED
Description
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
| Vendor | Product | Versions |
|---|---|---|
n/a | Undertow | affected Undertow 2.2.0.Final |
Weaknesses (CWE)
References
https://bugzilla.redhat.com/show_bug.cgi?id=1785049
x_refsource_MISC
[cxf-dev] 20210129 Undertow CVE
mailing-list
x_refsource_MLIST
https://security.netapp.com/advisory/ntap-20220210-0015/
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now