Bug#885338: undertow: CVE-2017-7559: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)

2018-05-07 Thread Salvatore Bonaccorso
Hi On Fri, Mar 02, 2018 at 07:09:10PM +0100, Markus Koschany wrote: > Control: forwarded -1 https://issues.jboss.org/browse/UNDERTOW-1251 > > It seems this issue is tracked at > > https://issues.jboss.org/browse/UNDERTOW-1251 > > However the bug report appears to be a duplicate of UNDERTOW-1101

Bug#885338: undertow: CVE-2017-7559: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)

2018-03-02 Thread Markus Koschany
Control: forwarded -1 https://issues.jboss.org/browse/UNDERTOW-1251 It seems this issue is tracked at https://issues.jboss.org/browse/UNDERTOW-1251 However the bug report appears to be a duplicate of UNDERTOW-1101 which was CVE-2017-2666 last year. I added a comment and hope that someone can cla

Bug#885338: undertow: CVE-2017-7559: HTTP Request smuggling vulnerability (incomplete fix of CVE-2017-2666)

2017-12-28 Thread Markus Koschany
On Thu, 28 Dec 2017 09:55:12 +0100 Salvatore Bonaccorso wrote: > Source: undertow > Severity: important > Tags: security > > Hi, > > the following vulnerability was published for undertow. > > There is not much information available if that incomplete fix affects > us as well. Or which this was