Description
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Remediation
References
http://rhn.redhat.com/errata/RHSA-2016-1838.html
http://rhn.redhat.com/errata/RHSA-2016-1839.html
http://rhn.redhat.com/errata/RHSA-2016-1840.html
http://rhn.redhat.com/errata/RHSA-2016-1841.html
http://www.securityfocus.com/bid/92894
http://www.securitytracker.com/id/1036758
https://access.redhat.com/errata/RHSA-2017:3454
https://access.redhat.com/errata/RHSA-2017:3455
https://access.redhat.com/errata/RHSA-2017:3456
https://access.redhat.com/errata/RHSA-2017:3458
https://bugzilla.redhat.com/show_bug.cgi?id=1344321
Related Vulnerabilities
CVE-2023-34612 Vulnerability in maven package com.helger.commons:ph-json
CVE-2020-2165 Vulnerability in maven package org.jenkins-ci.plugins:artifactory
CVE-2018-20822 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.twbs:bootstrap
CVE-2018-16459 Vulnerability in maven package org.webjars.npm:exceljs