漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
It was discovered in Undertow that the code that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack, or obtain sensitive information from requests other than their own.
CVSS Information
N/A
Vulnerability Type
HTTP请求的解释不一致性(HTTP请求私运)
Vulnerability Title
Red Hat Undertow 环境问题漏洞
Vulnerability Description
Red Hat Undertow是美国红帽(Red Hat)公司的一款Web服务器。 Red Hat Undertow中存在安全绕过漏洞。远程攻击者可通过操纵HTTP请求利用该漏洞造成Web缓存中毒,执行跨站脚本攻击或获取敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A