Red Hat · Undertow · CVE-2019-10184
Name of the Vulnerable Software and Affected Versions:
undertow versions prior to 2.0.23.Final
Description:
The issue allows web apps to have their directory structures predicted through requests without trailing slashes via the API. This is an information leak issue.
Recommendations:
For versions prior to 2.0.23.Final, update to version 2.0.23.Final or later to resolve the issue. As a temporary workaround, consider restricting access to the API to minimize the risk of exploitation. Avoid making requests without trailing slashes to affected web apps until the issue is resolved.