Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-10184

Опубликовано: 25 июл. 2019
Источник: debian
EPSS Низкий

Описание

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowfixed2.0.23-1package

Примечания

  • https://issues.jboss.org/browse/UNDERTOW-1578

  • https://github.com/undertow-io/undertow/pull/794

EPSS

Процентиль: 88%
0.03478
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 5.3
redhat
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
nvd
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
github
около 7 лет назад

Undertow Missing Authorization when requesting a protected directory without trailing slash

EPSS

Процентиль: 88%
0.03478
Низкий