← back
CVE-2020-10687

CVE-2020-10687

EPSS 1.1%CWE-444
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
23 Sep 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A flaw was discovered in all versions of Undertow before Undertow 2.2.0.Final, where HTTP request smuggling related to CVE-2017-2666 is possible against HTTP/1.x and HTTP/2 due to permitting invalid characters in an HTTP request. This flaw allows an attacker to poison a web-cache, perform an XSS attack, or obtain sensitive information from request other than their own.
Affected products
n/a · Undertow

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →