Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. io.undertow/undertow-core
  4. ›
  5. CVE-2016-4993

CVE-2016-4993: Improper Neutralization of CRLF Sequences in HTTP Headers

September 26, 2016 (updated December 14, 2017)

CRLF injection vulnerability in the Undertow web server allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

References

  • access.redhat.com/security/cve/CVE-2016-4993

Code Behaviors & Features

Detect and mitigate CVE-2016-4993 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 2.alpha0 up to 2.0.0, all versions starting from 1 up to 1.3.4

Fixed versions

  • 1.4.0
  • 2.0.1

Solution

Upgrade to versions 1.4.0, 2.0.1 or above.

Impact 6.1 MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

Source file

maven/io.undertow/undertow-core/CVE-2016-4993.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:34 +0000.