Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2w73-fqqj-c92p

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.1

Описание

Improper Input Validation in Undertow

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

<= 2.0.42

2.1.0

EPSS

Процентиль: 64%
0.00463
Низкий

8.1 High

CVSS3

Дефекты

CWE-20
CWE-200

Связанные уязвимости

CVSS3: 8.1
ubuntu
почти 6 лет назад

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

CVSS3: 8.1
redhat
около 7 лет назад

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

CVSS3: 8.1
nvd
почти 6 лет назад

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

CVSS3: 8.1
debian
почти 6 лет назад

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow- ...

EPSS

Процентиль: 64%
0.00463
Низкий

8.1 High

CVSS3

Дефекты

CWE-20
CWE-200