CVE-2017-12165

Impact:
Low
Public Date:
2017-12-13
CWE:
CWE-444
Bugzilla:
1490301: CVE-2017-12165 undertow: improper whitespace parsing leading to potential HTTP request smuggling
It was discovered that Undertow processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Find out more about CVE-2017-12165 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 2.6
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N
Attack Vector Network
Attack Complexity High
Privileges Required Low
User Interaction Required
Scope Unchanged
Confidentiality None
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2018:0005 2018-01-03
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-undertow) RHSA-2018:0002 2018-01-03
Red Hat JBoss EAP 7 RHSA-2018:0003 2018-01-03
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-undertow) RHSA-2017:3454 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-undertow) RHSA-2017:3455 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-undertow) RHSA-2018:0004 2018-01-03
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2018:0005 2018-01-03
Red Hat JBoss Fuse 6.3 RHSA-2018:1322 2018-05-03
Red Hat JBoss EAP 7 RHSA-2017:3456 2017-12-13
Red Hat JBoss A-MQ 6.3 RHSA-2018:1322 2018-05-03

Affected Packages State

Platform Package State
Red Hat Virtualization 4 eap7-undertow Affected
Red Hat Single Sign-On 7 wildfly-undertow Under investigation
Red Hat JBoss Fuse 7 undertow Not affected
Red Hat JBoss Data Grid 7 wildfly-undertow Under investigation

Acknowledgements

This issue was discovered by Stuart Douglas (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.