PT-2014-8289 · Red Hat · Jboss Undertow
Arun Neelicattu
·
Published
2014-12-01
·
Updated
2022-05-17
·
CVE-2014-7816
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
JBoss Undertow versions 1.0.x through 1.0.16
JBoss Undertow versions 1.1.x through 1.1.0.CR4
JBoss Undertow versions 1.2.x through 1.2.0.Beta2
Description
A directory traversal issue allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI when running on Windows.
Recommendations
For JBoss Undertow versions 1.0.x through 1.0.16, update to version 1.0.17 or later.
For JBoss Undertow versions 1.1.x through 1.1.0.CR4, update to version 1.1.0.CR5 or later.
For JBoss Undertow versions 1.2.x through 1.2.0.Beta2, update to version 1.2.0.Beta3 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jboss Undertow