CVE-2017-12165
27.07.2018, 15:29
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Vendor | Product | Version |
---|---|---|
redhat | undertow | 1.0.0 ≤ 𝑥 < 1.3.31 |
redhat | undertow | 1.4.0 ≤ 𝑥 < 1.4.17 |
redhat | undertow | 2.0.0:alpha_1 |
redhat | jboss_enterprise_application_platform | 7.0.0 |
redhat | jboss_enterprise_application_platform | 7.1.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
undertow |
|
References