Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f3rq-463v-2j36

Опубликовано: 27 авг. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

EPSS

Процентиль: 50%
0.00269
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-200
CWE-22

Связанные уязвимости

CVSS3: 4.8
redhat
больше 4 лет назад

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

CVSS3: 4.8
nvd
больше 3 лет назад

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

EPSS

Процентиль: 50%
0.00269
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-200
CWE-22