V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2017-2666
DEB
MediumConfirmedExploit available

It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in con…

CVSS
6.5
Medium
EPSS
0.03
p84
Published
2017-01-01
Updated
2017-01-01
Description

It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.

Tags · CWE
Pre-auth
CWE-444
CAPEC-33
CAPEC-273
Affected products
Eap7-activemq-artemisEap7-activemq-artemisEap7-activemq-artemisEap7-activemq-artemisEap7-antlrEap7-antlrEap7-apache-commons-beanutilsEap7-apache-commons-beanutilsEap7-apache-commons-cliEap7-apache-commons-cliEap7-apache-commons-ioEap7-apache-commons-ioEap7-apache-cxfEap7-apache-cxfEap7-apache-cxfEap7-apache-cxfEap7-apache-cxf-xjc-utilsEap7-apache-cxf-xjc-utilsEap7-apache-mime4jEap7-apache-mime4j
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Timeline
2017-01-01
Published
2017-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.027 · p84
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2017-2666
github-poc · https://github.com/tafamace/CVE-2017-2666
Enterprise
Affected products
ProductVendorStatus
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-antlrTracked
eap7-antlrTracked
eap7-apache-commons-beanutilsTracked
eap7-apache-commons-beanutilsTracked
eap7-apache-commons-cliTracked
eap7-apache-commons-cliTracked
eap7-apache-commons-ioTracked
eap7-apache-commons-ioTracked
eap7-apache-cxfTracked
eap7-apache-cxfTracked
eap7-apache-cxfTracked
eap7-apache-cxfTracked
eap7-apache-cxf-xjc-utilsTracked
eap7-apache-cxf-xjc-utilsTracked
eap7-apache-mime4jTracked
eap7-apache-mime4jTracked
Showing first 20 of 360
Source databases
DEB
CVE
RED
UBU