{"id":"GHSA-rj76-h87p-r3wf","summary":"Undertow vulnerable to Request Smuggling","details":"In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.","aliases":["CVE-2017-7559"],"modified":"2023-11-01T04:48:19.261874Z","published":"2022-05-13T01:36:16Z","database_specific":{"cwe_ids":["CWE-444"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-11-08T12:48:58Z","nvd_published_at":"2018-01-10T15:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-7559"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-7559"},{"type":"PACKAGE","url":"https://github.com/undertow-io/undertow"},{"type":"WEB","url":"https://issues.jboss.org/browse/UNDERTOW-1251"}],"affected":[{"package":{"name":"io.undertow:undertow-core","ecosystem":"Maven","purl":"pkg:maven/io.undertow/undertow-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.4.0"},{"fixed":"1.4.17.Final"}]}],"versions":["1.4.0.Final","1.4.1.Final","1.4.10.Final","1.4.11.Final","1.4.12.Final","1.4.13.Final","1.4.14.Final","1.4.15.Final","1.4.16.Final","1.4.2.Final","1.4.3.Final","1.4.4.Final","1.4.5.Final","1.4.6.Final","1.4.7.Final","1.4.8.Final","1.4.9.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rj76-h87p-r3wf/GHSA-rj76-h87p-r3wf.json"}},{"package":{"name":"io.undertow:undertow-core","ecosystem":"Maven","purl":"pkg:maven/io.undertow/undertow-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.3.0"},{"fixed":"1.3.31.Final"}]}],"versions":["1.3.0.Final","1.3.1.Final","1.3.10.Final","1.3.11.Final","1.3.12.Final","1.3.13.Final","1.3.14.Final","1.3.15.Final","1.3.16.Final","1.3.17.Final","1.3.18.Final","1.3.19.Final","1.3.2.Final","1.3.20.Final","1.3.21.Final","1.3.22.Final","1.3.23.Final","1.3.24.Final","1.3.25.Final","1.3.26.Final","1.3.27.Final","1.3.28.Final","1.3.29.Final","1.3.3.Final","1.3.30.Final","1.3.4.Final","1.3.5.Final","1.3.6.Final","1.3.7.Final","1.3.8.Final","1.3.9.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rj76-h87p-r3wf/GHSA-rj76-h87p-r3wf.json"}},{"package":{"name":"io.undertow:undertow-core","ecosystem":"Maven","purl":"pkg:maven/io.undertow/undertow-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0.Alpha1"},{"fixed":"2.0.0.Alpha2"}]}],"versions":["2.0.0.Alpha1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rj76-h87p-r3wf/GHSA-rj76-h87p-r3wf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}