Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10184

Опубликовано: 24 июл. 2019
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform 6jbosswebOut of support scope
Red Hat JBoss Fuse 6spring-bootOut of support scope
Red Hat JBoss Fuse 6undertowOut of support scope
Red Hat OpenShift Application RuntimesundertowAffected
Red Hat Process Automation 7undertowNot affected
Red Hat support for Spring BootundertowNot affected
Red Hat Data Grid 7.3.3undertowFixedRHSA-2020:072705.03.2020
Red Hat Fuse 7.6.0undertowFixedRHSA-2020:098326.03.2020
Red Hat JBoss EAP 7.2FixedRHSA-2019:293830.09.2019
Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6eap7-activemq-artemisFixedRHSA-2019:293501.10.2019

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-862
https://bugzilla.redhat.com/show_bug.cgi?id=1713068undertow: Information leak in requests for directories without trailing slashes

EPSS

Процентиль: 71%
0.0068
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
nvd
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

CVSS3: 7.5
debian
больше 6 лет назад

undertow before version 2.0.23.Final is vulnerable to an information l ...

CVSS3: 7.5
github
больше 6 лет назад

Undertow Missing Authorization when requesting a protected directory without trailing slash

EPSS

Процентиль: 71%
0.0068
Низкий

5.3 Medium

CVSS3