Man-in-the-middle attack in Undertow - CVE-2017-12196

 

Man-in-the-middle attack in Undertow - CVE-2017-12196

Published: May 17, 2018


Vulnerability identifier: #VU12802
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-12196
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to obtain potentially sensitive information on the target system.

The weakness exists due to the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line when using Digest authentication. A remote attacker can conduct man-in-the-middle attack and gin access to potentially sensitive information.

Affected software

Undertow
Red Hat Virtualization
Red Hat Virtualization Host
openEuler
undertow
undertow-javadoc
eap7-jboss-ec2-eap (Red Hat package)

How to mitigate CVE-2017-12196

Update to versions 1.4.18.SP1, 2.0.2.Final or 1.4.24.Final.

undertow - update to 1.4.0-10
undertow-javadoc - update to 1.4.0-10
eap7-jboss-ec2-eap (Red Hat package) - addressed in versions 7.1.1-3.1.GA_redhat_3.ep7.el6, 7.1.1-3.1.GA_redhat_3.ep7.el7

External References

Related Security Bulletins