CVE-2017-2666

Impact:
Moderate
Public Date:
2017-06-07
CWE:
CWE-444
Bugzilla:
1436163: CVE-2017-2666 undertow: HTTP Request smuggling vulnerability due to permitting invalid characters in HTTP requests
It was discovered that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.

Find out more about CVE-2017-2666 from the MITRE CVE dictionary dictionary and NIST NVD.

CVSS v3 metrics

CVSS3 Base Score 6.5
CVSS3 Base Metrics CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Low
Integrity Impact Low
Availability Impact None

Red Hat Security Errata

Platform Errata Release Date
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:3458 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2017:1411 2017-06-07
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server (eap7-jboss-ec2-eap) RHSA-2017:1412 2017-06-07
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2017:3454 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7 Server RHSA-2017:3455 2017-12-13
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server (eap7-jboss-ec2-eap) RHSA-2017:1412 2017-06-07
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6 Server RHSA-2017:1410 2017-06-07
Red Hat JBoss EAP 7 RHSA-2017:1409 2017-06-07
Red Hat JBoss EAP 7 RHSA-2017:3456 2017-12-13

Affected Packages State

Platform Package State
Red Hat Single Sign-On 7 wildfly-undertow Will not fix
Red Hat JBoss Fuse 6 wildfly-undertow Will not fix

Acknowledgements

This issue was discovered by Radim Hatlapatka (Red Hat).

Last Modified
Close

Welcome! Check out the Getting Started with Red Hat page for quick tours and guides for common tasks.