Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1047

Опубликовано: 17 дек. 2017
Источник: redhat
CVSS3: 8.6
EPSS Низкий

Описание

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

A path traversal vulnerability was discovered in Undertow's org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method. This could lead to information disclosure of arbitrary local files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
JBoss Developer Studio 10wildfly-undertowOut of support scope
Red Hat Fuse 7undertowAffected
Red Hat JBoss Data Grid 7wildfly-undertowNot affected
Red Hat JBoss Fuse 6undertowWill not fix
Red Hat JBoss Fuse Integration Service 2undertowAffected
Red Hat OpenShift Application RuntimesundertowAffected
Red Hat Single Sign-On 7wildflyNot affected
Red Hat Single Sign-On 7wildfly-undertowNot affected
Red Hat JBoss EAP 7.1FixedRHSA-2018:125125.04.2018
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6eap7-activemq-artemisFixedRHSA-2018:124825.04.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20->CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1528361undertow: Path traversal in ServletResourceManager class

EPSS

Процентиль: 39%
0.00176
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS3: 5.5
nvd
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS3: 5.5
debian
около 8 лет назад

A flaw was found in Wildfly 9.x. A path traversal vulnerability throug ...

CVSS3: 5.5
github
больше 7 лет назад

Improper Input Validation in org.wildfly:wildfly-undertow

EPSS

Процентиль: 39%
0.00176
Низкий

8.6 High

CVSS3