HTTP Request Smuggling Affecting undertow package, versions <2.2.0-1


Severity

Recommended
0.0
medium
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
0.31% (54th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-UNDERTOW-1085956
  • published16 Mar 2021
  • disclosed23 Feb 2021

Introduced: 23 Feb 2021

CVE-2021-20220  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade Debian:unstable undertow to version 2.2.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream undertow package and not the undertow package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS Base Scores

version 3.1