undertow before versions 1.4.18.SP1, 2.0.2.Final, 1.4.24.Final was found vulnerable when using Digest authentication, the server does not ensure that the value of URI in the Authorization header matches the URI in HTTP request line. This allows the attacker to cause a MITM attack and access the desired content on the server.
History

Fri, 23 Aug 2024 05:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-04-18T01:00:00

Updated: 2024-08-05T18:28:16.713Z

Reserved: 2017-08-01T00:00:00

Link: CVE-2017-12196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-04-18T01:29:01.443

Modified: 2024-11-21T03:09:01.960

Link: CVE-2017-12196

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-03-12T15:56:00Z

Links: CVE-2017-12196 - Bugzilla