Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1550671 - (CVE-2018-1067) CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding (incomplete fix of CVE-2016-4993)
CVE-2018-1067 undertow: HTTP header injection using CRLF with UTF-8 Encoding ...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180425:1751,...
: Security
Depends On: 1592645 1592646 1592647 1591095
Blocks: 1550674
  Show dependency treegraph
 
Reported: 2018-03-01 13:45 EST by Laura Pardo
Modified: 2018-10-19 17:47 EDT (History)
93 users (show)

See Also:
Fixed In Version: undertow 7.1.2.CR1, undertow 7.1.2.GA
Doc Type: If docs needed, set a value
Doc Text:
It was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient sanitization and validation of user input before the input is used as part of an HTTP header value.
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:1247 None None None 2018-04-25 14:25 EDT
Red Hat Product Errata RHSA-2018:1248 None None None 2018-04-25 14:23 EDT
Red Hat Product Errata RHSA-2018:1249 None None None 2018-04-25 14:37 EDT
Red Hat Product Errata RHSA-2018:1251 normal SHIPPED_LIVE Important: Red Hat JBoss Enterprise Application Platform 7.1.2 security update 2018-04-25 19:43:26 EDT
Red Hat Product Errata RHSA-2018:2643 None None None 2018-09-04 09:45 EDT

  None (edit)
Description Laura Pardo 2018-03-01 13:45:08 EST
A flaw was reported in WildFly 12.0.0.CR1 web server is vulnerable to the injection of arbitrary HTTP Header due to insufficient sanitisation and validation of user UTF-8 encoded input before it is used as part of an HTTP header value.

Although there is a protection against CRLF injection by detecting the presence of a NewLine character (0x0a), it can be bypassed using characters encoded in UTF-8 as the page will try to convert them back to the original Unicode form and extract the last byte.
Comment 1 Bharti Kundal 2018-03-05 19:54:55 EST
Acknowledgments:

Name: Ammarit Thongthua (Deloitte Thailand Pentest team), Nattakit Intarasorn (Deloitte Thailand Pentest team)
Comment 4 errata-xmlrpc 2018-04-25 14:22:36 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2018:1248 https://access.redhat.com/errata/RHSA-2018:1248
Comment 5 errata-xmlrpc 2018-04-25 14:25:20 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7

Via RHSA-2018:1247 https://access.redhat.com/errata/RHSA-2018:1247
Comment 6 errata-xmlrpc 2018-04-25 14:36:37 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
  Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6

Via RHSA-2018:1249 https://access.redhat.com/errata/RHSA-2018:1249
Comment 7 errata-xmlrpc 2018-04-25 15:45:13 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Enterprise Application Platform

Via RHSA-2018:1251 https://access.redhat.com/errata/RHSA-2018:1251
Comment 11 Doran Moppert 2018-06-18 23:57:42 EDT
Created tomcat tracking bugs for this issue:

Affects: fedora-all [bug 1592646]


Created undertow tracking bugs for this issue:

Affects: fedora-all [bug 1592647]


Created wildfly tracking bugs for this issue:

Affects: fedora-all [bug 1592645]
Comment 12 errata-xmlrpc 2018-09-04 09:44:55 EDT
This issue has been addressed in the following products:

  Red Hat Virtualization 4 for Red Hat Enterprise Linux 7

Via RHSA-2018:2643 https://access.redhat.com/errata/RHSA-2018:2643

Note You need to log in before you can comment on or make changes to this bug.