RedHat RESTEasy CVE-2017-7561 HTTP Header Injection Vulnerability
BID:100465
CVE-2017-7561 |Info
RedHat RESTEasy CVE-2017-7561 HTTP Header Injection Vulnerability
| Bugtraq ID: | 100465 |
| Class: | Design Error |
| CVE: |
CVE-2017-7561 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 22 2017 12:00AM |
| Updated: | Aug 22 2017 12:00AM |
| Credit: | Jason Shepherd (Red Hat Product Security). |
| Vulnerable: |
Redhat Resteasy 3.1.4 Redhat Resteasy 3.1.3 Redhat Resteasy 3.1.1 Redhat Resteasy 3.1 Redhat Resteasy 3.0.24 Redhat Resteasy 3.0.23 Redhat Resteasy 3.0.21 Redhat Resteasy 3.0.19 Redhat Resteasy 3.0.18 Redhat Resteasy 3.0.17 Redhat Resteasy 3.0.12 Redhat Resteasy 3.0.11 Redhat Resteasy 3.0.10 Redhat Resteasy 3.1.2 Redhat Resteasy 3.0.9 Redhat Resteasy 3.0.8 Redhat Resteasy 3.0.7 Redhat Resteasy 3.0.22 Redhat JBoss Fuse 6.0 Redhat Jboss EAP 7.0 Redhat JBoss Data Grid 7.0.0 Redhat JBoss A-MQ 6.0 |
| Not Vulnerable: | |
Discussion
RedHat RESTEasy CVE-2017-7561 HTTP Header Injection Vulnerability
RedHat RESTEasy is prone to an HTTP header-injection vulnerability.
An attacker can exploit this issue to inject arbitrary HTTP headers into a server response that could help to bypass security controls, perform cache poisoning and alter request or response page. This may aid in further attacks.
RedHat RESTEasy 3.0.7 and later are vulnerable.
RedHat RESTEasy is prone to an HTTP header-injection vulnerability.
An attacker can exploit this issue to inject arbitrary HTTP headers into a server response that could help to bypass security controls, perform cache poisoning and alter request or response page. This may aid in further attacks.
RedHat RESTEasy 3.0.7 and later are vulnerable.