Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wq8g-hm94-5rqq

Опубликовано: 23 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

JBoss AS may expose root content if excluded-contexts list is mismatched

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

Пакеты

Наименование

org.jboss.as:jboss-as-server

maven
Затронутые версииВерсия исправления

>= 7.0.0.Alpha1, < 7.1.1.Final

7.1.1.Final

EPSS

Процентиль: 46%
0.00235
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

redhat
около 14 лет назад

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

CVSS3: 7.5
nvd
почти 6 лет назад

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostname in the same way, which can cause the excluded-contexts list to be mismatched and the root context to be exposed.

CVSS3: 7.5
debian
почти 6 лет назад

JBoss AS 7 prior to 7.1.1 and mod_cluster do not handle default hostna ...

EPSS

Процентиль: 46%
0.00235
Низкий

7.5 High

CVSS3

Дефекты

CWE-200