PT-2014-8289 · Red Hat · Jboss Undertow

Arun Neelicattu

·

Publicado

2014-12-01

·

Atualizado

2022-05-17

·

CVE-2014-7816

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Undertow versions 1.0.x through 1.0.16 JBoss Undertow versions 1.1.x through 1.1.0.CR4 JBoss Undertow versions 1.2.x through 1.2.0.Beta2
Description A directory traversal issue allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI when running on Windows.
Recommendations For JBoss Undertow versions 1.0.x through 1.0.16, update to version 1.0.17 or later. For JBoss Undertow versions 1.1.x through 1.1.0.CR4, update to version 1.1.0.CR5 or later. For JBoss Undertow versions 1.2.x through 1.2.0.Beta2, update to version 1.2.0.Beta3 or later.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2014-7816
GHSA-H6P6-FC4W-CQHX

Produtos afetados

Jboss Undertow