Security Advisory

CVE-2020-10687

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-09-23 12:30:43
Last updated 2024-08-04 11:06:11
Assigner redhat
State PUBLISHED

Description

A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.