Candidate: CVE-2017-12165 PublicDate: 2018-07-27 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12165 https://bugzilla.redhat.com/show_bug.cgi?id=1490301 Description: It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_undertow: upstream_undertow: needed precise/esm_undertow: DNE trusty_undertow: DNE trusty/esm_undertow: DNE xenial_undertow: ignored (end of standard support, was needed) zesty_undertow: ignored (reached end-of-life) artful_undertow: ignored (reached end-of-life) bionic_undertow: needed cosmic_undertow: ignored (reached end-of-life) disco_undertow: ignored (reached end-of-life) eoan_undertow: released (2.0.23-1) focal_undertow: released (2.0.23-1) groovy_undertow: released (2.0.23-1) hirsute_undertow: released (2.0.23-1) impish_undertow: released (2.0.23-1) jammy_undertow: released (2.0.23-1) devel_undertow: released (2.0.23-1)