Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.wildfly/wildfly-undertow
  4. ›
  5. CVE-2016-4993

CVE-2016-4993: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')

May 17, 2022 (updated July 12, 2022)

CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

References

  • rhn.redhat.com/errata/RHSA-2016-1838.html
  • rhn.redhat.com/errata/RHSA-2016-1839.html
  • rhn.redhat.com/errata/RHSA-2016-1840.html
  • rhn.redhat.com/errata/RHSA-2016-1841.html
  • access.redhat.com/errata/RHSA-2017:3454
  • access.redhat.com/errata/RHSA-2017:3455
  • access.redhat.com/errata/RHSA-2017:3456
  • access.redhat.com/errata/RHSA-2017:3458
  • bugzilla.redhat.com/show_bug.cgi?id=1344321
  • github.com/advisories/GHSA-qcqr-hcjq-whfq
  • github.com/undertow-io/undertow/commit/834496fb74ddda2af197940c70d08bab419fdf12
  • issues.redhat.com/browse/UNDERTOW-827
  • nvd.nist.gov/vuln/detail/CVE-2016-4993

Code Behaviors & Features

Detect and mitigate CVE-2016-4993 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 10.0.0.final up to 10.1.0.final

Fixed versions

  • 11.0.0.Final

Solution

Upgrade to version 11.0.0.Final or above.

Impact 6.1 MEDIUM

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-113: Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')
  • CWE-93: Improper Neutralization of CRLF Sequences ('CRLF Injection')

Source file

maven/org.wildfly/wildfly-undertow/CVE-2016-4993.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:07 +0000.