Description
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2009-3413 Vulnerability (CVE-2009-3413)
WebLogic CVE-2020-14639 Vulnerability (CVE-2020-14639)
WordPress Plugin WPS Hide Login Multiple Security Bypass Vulnerabilities (1.5.2.2)
WordPress Plugin Mingle Forum SQL Injection and Security Bypass Vulnerabilities (1.0.26)
Nginx Resource Management Errors Vulnerability (CVE-2016-0747)