CVE-2017-12165

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2018
Last modified:
17/06/2026

Description

It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* 1.0.0 (including) 1.3.31 (excluding)
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* 1.4.0 (including) 1.4.17 (excluding)
cpe:2.3:a:redhat:undertow:2.0.0:alpha_1:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1.0:*:*:*:*:*:*:*