[GHSA-j382-5jj3-vw4j] Undertow HTTP server core doesn't properly validate the Host header in incoming HTTP requests#7105
Open
aogburn wants to merge 1 commit intoaogburn/advisory-improvement-7105from
Conversation
Author
|
The Undertow SP releases would generally be JBoss EAP specific patch tags and so aren't issued on the default central maven repo. They are issued on the Red Hat maven repo and this would be the actual jar version provided in EAP 8.1 errata like https://access.redhat.com/errata/RHSA-2026:0384 noted in this advisory. 2.3.20.SP2 was never formally released publicly so if we want to keep the advisory to a public release, then we can reference 2.3.20.SP4-redhat-00001 instead of 2.3.20.SP2. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Updates
Comments
This is also addressed in Undertow 2.3.20.SP2 so checking/expecting 2.3.21.Final only will result in false positives against the fixed undertow 2.3.20.SP4-redhat-00001 in EAP 8.1 update 3 and later.