CVE-2017-7559
MEDIUMUndertow <2.0.0.Alpha2,<1.4.17.Final,<1.3.31.Final - SSRF
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-7559. PoCs published by dawetmaster, andikahilmy.
AI-analyzed exploit summary The repository contains only the source code of Undertow, a Java web server, without any exploit code or technical analysis related to CVE-2017-7559. The README is a generic description of Undertow, and the files are standard Undertow source files.
Description
In Undertow 2.x before 2.0.0.Alpha2, 1.4.x before 1.4.17.Final, and 1.3.x before 1.3.31.Final, it was found that the fix for CVE-2017-2666 was incomplete and invalid characters are still allowed in the query string and path parameters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
Exploits (2)
The repository contains only the source code of Undertow, a Java web server, without any exploit code or technical analysis related to CVE-2017-7559. The README is a generic description of Undertow, and the files are standard Undertow source files.
The repository contains a partial snapshot of the Undertow web server source code but lacks any exploit code or technical analysis related to CVE-2017-7559. The README is a generic description of Undertow without vulnerability details.
References (11)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N