Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w69w-jvc7-wjgv

Опубликовано: 01 авг. 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undertow Missing Authorization when requesting a protected directory without trailing slash

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

Пакеты

Наименование

io.undertow:undertow-servlet

maven
Затронутые версииВерсия исправления

< 2.0.23

2.0.23

EPSS

Процентиль: 88%
0.03478
Низкий

7.5 High

CVSS3

Дефекты

CWE-862

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 5.3
redhat
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
nvd
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
debian
около 7 лет назад

undertow before version 2.0.23.Final is vulnerable to an information l ...

EPSS

Процентиль: 88%
0.03478
Низкий

7.5 High

CVSS3

Дефекты

CWE-862