HTTP Request Smuggling Affecting eap7-ironjacamar package, versions <0:1.4.27-1.Final_redhat_00001.1.el7eap


Severity

Recommended
0.0
medium
0
10

Based on Red Hat Enterprise Linux security rating.

Threat Intelligence

EPSS
0.07% (34th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-RHEL7-EAP7IRONJACAMAR-5344323
  • published30 Mar 2023
  • disclosed4 Feb 2021

Introduced: 4 Feb 2021

CVE-2021-20220  (opens in a new tab)
CWE-444  (opens in a new tab)

How to fix?

Upgrade RHEL:7 eap7-ironjacamar to version 0:1.4.27-1.Final_redhat_00001.1.el7eap or higher.
This issue was patched in RHSA-2021:0873.

NVD Description

Note: Versions mentioned in the description apply only to the upstream eap7-ironjacamar package and not the eap7-ironjacamar package as distributed by RHEL. See How to fix? for RHEL:7 relevant fixed versions and status.

A flaw was found in Undertow. A regression in the fix for CVE-2020-10687 was found. HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS Base Scores

version 3.1