logo

CVE-2017-12196 io.undertow:undertow-core

Package

Manager: maven
Name: io.undertow:undertow-core
Vulnerable Version: >=2.0.0.alpha1 <2.0.2.final || >=0 <1.4.24.final

Severity

Level: Medium

CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N

EPSS: 0.00226 pctl0.45259

Details

Incorrect Authorization in Undertow Undertow before versions 1.4.18.SP1 (not findable in Maven), 2.0.2.Final, and 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.

Metadata

Created: 2022-05-13T01:38:10Z
Modified: 2022-07-01T21:34:47Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-cp7v-vmv7-6x2q/GHSA-cp7v-vmv7-6x2q.json
CWE IDs: ["CWE-863"]
Alternative ID: GHSA-cp7v-vmv7-6x2q
Finding: F006
Auto approve: 1