Description
CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.
Remediation
References
http://www.securitytracker.com/id/1036758
http://rhn.redhat.com/errata/RHSA-2016-1838.html
http://rhn.redhat.com/errata/RHSA-2016-1840.html
http://rhn.redhat.com/errata/RHSA-2016-1841.html
https://bugzilla.redhat.com/show_bug.cgi?id=1344321
http://rhn.redhat.com/errata/RHSA-2016-1839.html
http://www.securityfocus.com/bid/92894
https://access.redhat.com/errata/RHSA-2017:3458
https://access.redhat.com/errata/RHSA-2017:3456
https://access.redhat.com/errata/RHSA-2017:3455
https://access.redhat.com/errata/RHSA-2017:3454
Related Vulnerabilities
CVE-2021-21266 Vulnerability in maven package org.openhab.addons.bundles:org.openhab.binding.sonos
CVE-2017-16084 Vulnerability in npm package list-n-stream
CVE-2022-28367 Vulnerability in maven package org.owasp:antisamy
CVE-2018-1229 Vulnerability in maven package org.springframework.batch:spring-batch-admin
CVE-2023-43495 Vulnerability in maven package org.jenkins-ci.main:jenkins-core