CVE-2017-12196 – io.undertow:undertow-core
Package
Manager: maven
Name: io.undertow:undertow-core
Vulnerable Version: >=2.0.0.alpha1 <2.0.2.final || >=0 <1.4.24.final
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00226 pctl0.45259
Details
Incorrect Authorization in Undertow Undertow before versions 1.4.18.SP1 (not findable in Maven), 2.0.2.Final, and 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
Metadata
Created: 2022-05-13T01:38:10Z
Modified: 2022-07-01T21:34:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cp7v-vmv7-6x2q/GHSA-cp7v-vmv7-6x2q.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-cp7v-vmv7-6x2q
Finding: F006
Auto approve: 1