Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmr4-w67p-vh8x

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.5

Описание

Improper Input Validation in org.wildfly:wildfly-undertow

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

Пакеты

Наименование

org.wildfly:wildfly-undertow

maven
Затронутые версииВерсия исправления

< 12.0.0

12.0.0

EPSS

Процентиль: 39%
0.00176
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-22

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS3: 8.6
redhat
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS3: 5.5
nvd
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS3: 5.5
debian
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability throug ...

EPSS

Процентиль: 39%
0.00176
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-20
CWE-22