CVE-2020-1710
16.09.2020, 15:15
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | jboss_data_grid | - |
redhat | jboss_data_grid | 7.0.0 |
redhat | jboss_enterprise_application_platform | - |
redhat | jboss_enterprise_application_platform | 6.4.21 |
redhat | jboss_enterprise_application_platform | 7.0.0 |
redhat | jboss_enterprise_application_platform | 7.2.0 |
redhat | jboss_enterprise_application_platform | 7.3.0 |
redhat | openshift_application_runtimes | - |
redhat | single_sign-on | - |
𝑥
= Vulnerable software versions