CVE-2017-12165
LOWUndertow <1.4.17, <1.3.31, <2.0.0 - HTTP Request Smuggling
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-12165. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary The repository contains only the source code of Undertow, a Java web server, without any exploit code or technical analysis related to CVE-2017-12165. The README provides no details about the vulnerability or how to exploit it.
Description
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Exploits (2)
The repository contains only the source code of Undertow, a Java web server, without any exploit code or technical analysis related to CVE-2017-12165. The README provides no details about the vulnerability or how to exploit it.
The repository contains a partial snapshot of the Undertow web server source code but lacks any exploit code or technical analysis related to CVE-2017-12165. The README is a generic description of Undertow without vulnerability details.
References (10)
Scores
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:L/A:N