Description
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
References (11)
Scores
CVSS v3
6.1
EPSS
0.0148
EPSS Percentile
81.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-113
CWE-93
Status
published
Products (3)
org.wildfly/wildfly-undertow
10.0.0.Final - 11.0.0.FinalMaven
redhat/jboss_enterprise_application_platform
< 7.0.1
redhat/jboss_wildfly_application_server
10.0.0
Published
Sep 26, 2016
Tracked Since
Feb 18, 2026