REDHAT-BUG-2443260: High severity Red Hat Undertow vulnerability
Undertow allows \r\r\r as a header block terminator. This can be used for request smuggling with proxy servers that forwards this byte sequence, including older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2443260?
The severity of REDHAT-BUG-2443260 is critical due to the potential for request smuggling exploits.
How do I fix REDHAT-BUG-2443260?
To fix REDHAT-BUG-2443260, update to the latest version of Undertow, Apache Traffic Server, or Google Cloud Classic Application Load Balancer, as applicable.
Which software is affected by REDHAT-BUG-2443260?
REDHAT-BUG-2443260 affects Red Hat Undertow, Apache Traffic Server, and Google Cloud Classic Application Load Balancer.
What type of attack does REDHAT-BUG-2443260 enable?
REDHAT-BUG-2443260 enables a request smuggling attack that can compromise proxy servers.
Is REDHAT-BUG-2443260 exploitable in a production environment?
Yes, REDHAT-BUG-2443260 is exploitable in a production environment if the affected software is in use and unpatched.