CVE-2017-12196
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line.
Does this matter?
Lower severity and a low EPSS score (2.05%). Track it; it rarely justifies an emergency change on its own.
Description
undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.05% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287, CWE-863
- Affected
- redhat/undertow · redhat/jboss enterprise application platform · redhat/jboss fuse · redhat/virtualization
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2018:0478Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0479Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0480Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0481Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1525Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2405Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3768Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12196Issue Tracking, Vendor Advisory
- https://issues.jboss.org/browse/UNDERTOW-1190Issue Tracking
- https://access.redhat.com/errata/RHSA-2018:0478Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0479Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0480Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0481Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:1525Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:2405Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:3768Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2017-12196Issue Tracking, Vendor Advisory
- https://issues.jboss.org/browse/UNDERTOW-1190Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.