PT-2014-8289 · Red Hat · Jboss Undertow
Arun Neelicattu
·
Publicado
2014-12-01
·
Atualizado
2022-05-17
·
CVE-2014-7816
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss Undertow versions 1.0.x through 1.0.16
JBoss Undertow versions 1.1.x through 1.1.0.CR4
JBoss Undertow versions 1.2.x through 1.2.0.Beta2
Description
A directory traversal issue allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI when running on Windows.
Recommendations
For JBoss Undertow versions 1.0.x through 1.0.16, update to version 1.0.17 or later.
For JBoss Undertow versions 1.1.x through 1.1.0.CR4, update to version 1.1.0.CR5 or later.
For JBoss Undertow versions 1.2.x through 1.2.0.Beta2, update to version 1.2.0.Beta3 or later.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jboss Undertow