Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v76w-3ph8-vm66

Опубликовано: 12 фев. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Undertow Path Traversal vulnerability

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.31.Final

2.2.31.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.3.0.Alpha1, < 2.3.12.Final

2.3.12.Final

EPSS

Процентиль: 91%
0.06044
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-24

Связанные уязвимости

CVSS3: 5.3
ubuntu
почти 2 года назад

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

CVSS3: 5.3
redhat
около 2 лет назад

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

CVSS3: 5.3
nvd
почти 2 года назад

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

CVSS3: 5.3
debian
почти 2 года назад

A path traversal vulnerability was found in Undertow. This issue may a ...

EPSS

Процентиль: 91%
0.06044
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-24