Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w69w-jvc7-wjgv

Опубликовано: 01 авг. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undertow Missing Authorization when requesting a protected directory without trailing slash

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

Пакеты

Наименование

io.undertow:undertow-servlet

maven
Затронутые версииВерсия исправления

< 2.0.23

2.0.23

EPSS

Процентиль: 71%
0.0068
Низкий

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 5.3
redhat
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
nvd
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
debian
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information l ...

EPSS

Процентиль: 71%
0.0068
Низкий

7.5 High

CVSS3

Дефекты

CWE-862