Bugzilla will be upgraded to version 5.0. The upgrade date is tentatively scheduled for 2 December 2018, pending final testing and feedback.
Bug 1481665 - (CVE-2017-7559) CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666) [NEEDINFO]
CVE-2017-7559 undertow: HTTP Request smuggling vulnerability (incomplete fix ...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20171213,repor...
: Security
Depends On:
Blocks: 1481666 1520314 1527613
  Show dependency treegraph
 
Reported: 2017-08-15 08:01 EDT by Adam Mariš
Modified: 2018-10-19 17:42 EDT (History)
31 users (show)

See Also:
Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
It was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---
bkundal: needinfo? (sdouglas)


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2017:3454 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 17:48:09 EST
Red Hat Product Errata RHSA-2017:3455 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 17:57:25 EST
Red Hat Product Errata RHSA-2017:3456 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.0 security update 2017-12-13 17:31:03 EST
Red Hat Product Errata RHSA-2017:3458 normal SHIPPED_LIVE Important: eap7-jboss-ec2-eap security update 2017-12-13 18:26:13 EST
Red Hat Product Errata RHSA-2018:0002 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.0.9 security update on RHEL 6 2018-01-03 10:30:20 EST
Red Hat Product Errata RHSA-2018:0003 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.0.9 security update 2018-01-03 10:20:33 EST
Red Hat Product Errata RHSA-2018:0004 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.0.9 security update on RHEL 7 2018-01-03 10:31:14 EST
Red Hat Product Errata RHSA-2018:0005 normal SHIPPED_LIVE Important: eap7-jboss-ec2-eap security update 2018-01-03 10:49:39 EST
Red Hat Product Errata RHSA-2018:1322 None None None 2018-05-03 15:05 EDT

  None (edit)
Description Adam Mariš 2017-08-15 08:01:20 EDT
It was found that original patch for CVE-2017-2666 issue in undertow was incomplete and invalid characters are still allowed in the query string and path parameters.
Comment 1 Adam Mariš 2017-08-15 08:01:36 EDT
Acknowledgments:

Name: Stuart Douglas (Red Hat)
Comment 3 errata-xmlrpc 2017-12-13 12:37:17 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2017:3456 https://access.redhat.com/errata/RHSA-2017:3456
Comment 4 errata-xmlrpc 2017-12-13 13:29:13 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2017:3454 https://access.redhat.com/errata/RHSA-2017:3454
Comment 5 errata-xmlrpc 2017-12-13 13:44:57 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2017:3455 https://access.redhat.com/errata/RHSA-2017:3455
Comment 6 errata-xmlrpc 2017-12-13 13:55:21 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2017:3458 https://access.redhat.com/errata/RHSA-2017:3458
Comment 7 Salvatore Bonaccorso 2017-12-28 03:36:24 EST
Hi

Do you have any further information which upstream change fixes the issue? I sthere a upstream issue reported for that? 

Regards,
Salvatore
Comment 8 Fabio Olive Leite 2017-12-28 12:21:09 EST
Setting needinfo to Bharti Kundal so that she sees it.
Comment 11 errata-xmlrpc 2018-01-03 05:21:28 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:0003 https://access.redhat.com/errata/RHSA-2018:0003
Comment 12 errata-xmlrpc 2018-01-03 05:32:55 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6

Via RHSA-2018:0002 https://access.redhat.com/errata/RHSA-2018:0002
Comment 13 errata-xmlrpc 2018-01-03 05:35:05 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7

Via RHSA-2018:0004 https://access.redhat.com/errata/RHSA-2018:0004
Comment 14 errata-xmlrpc 2018-01-03 05:51:59 EST
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6

Via RHSA-2018:0005 https://access.redhat.com/errata/RHSA-2018:0005
Comment 15 Bharti Kundal 2018-01-04 03:18:51 EST
(In reply to Salvatore Bonaccorso from comment #7)
> Hi
> 
> Do you have any further information which upstream change fixes the issue? I
> sthere a upstream issue reported for that? 
> 
> Regards,
> Salvatore

Hi Salvatore,

The upstream JIRA is :https://issues.jboss.org/browse/UNDERTOW-1251 .You can get more information from there.

Thanks and Regards,
Bharti
Comment 16 Markus Koschany 2018-01-31 17:20:30 EST
We tried to find more information about CVE-2017-7559 and CVE-2017-12165 but could not find any in undertow's bug tracker. For both issues you pointed us to https://issues.jboss.org/browse/UNDERTOW-1251. 

UNDERTOW-1251 is about CVE-2017-2666 though. What are the corresponding issues for CVE-2017-7559 and CVE-2017-12165?

Thanks,

Markus
Comment 17 Yogendra Jog 2018-02-01 06:56:51 EST
Setting needinfo to Bharti Kundal so that she sees it.
Comment 20 errata-xmlrpc 2018-05-03 15:04:55 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse

Via RHSA-2018:1322 https://access.redhat.com/errata/RHSA-2018:1322

Note You need to log in before you can comment on or make changes to this bug.