#VU7548 HTTP response splitting in Undertow - CVE-2017-2666
Published: July 17, 2017
Undertow
Red Hat Inc.
Description
The vulnerability allows a remote attacker to perform a phishing attack
The vulnerability exists due to an error when processing headers in HTTP requests in Undertow. A remote attacker can create a specially crafted HTTP request, split the HTTP response from server and poison the web cache.
Successful exploitation of the vulnerability may allow an attacker to poison web cache and perform phishing or XSS attacks against website visitors.