PT-2014-8289 · Red Hat · Jboss Undertow

Arun Neelicattu

·

Published

2014-12-01

·

Updated

2022-05-17

·

CVE-2014-7816

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions JBoss Undertow versions 1.0.x through 1.0.16 JBoss Undertow versions 1.1.x through 1.1.0.CR4 JBoss Undertow versions 1.2.x through 1.2.0.Beta2
Description A directory traversal issue allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI when running on Windows.
Recommendations For JBoss Undertow versions 1.0.x through 1.0.16, update to version 1.0.17 or later. For JBoss Undertow versions 1.1.x through 1.1.0.CR4, update to version 1.1.0.CR5 or later. For JBoss Undertow versions 1.2.x through 1.2.0.Beta2, update to version 1.2.0.Beta3 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-7816
GHSA-H6P6-FC4W-CQHX

Affected Products

Jboss Undertow