CVE-2020-1710
16.09.2020, 15:15
The issue appears to be that JBoss EAP 6.4.21 does not parse the field-name in accordance to RFC7230[1] as it returns a 200 instead of a 400.Enginsight
| Vendor | Product | Version |
|---|---|---|
| redhat | jboss_data_grid | - |
| redhat | jboss_data_grid | 7.0.0 |
| redhat | jboss_enterprise_application_platform | - |
| redhat | jboss_enterprise_application_platform | 6.4.21 |
| redhat | jboss_enterprise_application_platform | 7.0.0 |
| redhat | jboss_enterprise_application_platform | 7.2.0 |
| redhat | jboss_enterprise_application_platform | 7.3.0 |
| redhat | openshift_application_runtimes | - |
| redhat | single_sign-on | - |
𝑥
= Vulnerable software versions