PT-2020-2761 · Red Hat · Undertow

Kunjan Rathod

·

Published

2020-04-28

·

Updated

2024-02-16

·

CVE-2020-1745

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Undertow versions 2.0.29.Final and before
Description A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009. This issue allows a remote, unauthenticated attacker to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution. The vulnerability is related to insufficient access control in the AJP Connector service.
Recommendations For Undertow versions 2.0.29.Final and before, update to version 2.0.30.Final to resolve the issue. As a temporary workaround, consider disabling the AJP connector or restricting access to the default AJP configuration port 8009 until a patch is applied. Additionally, restrict file uploads on the vulnerable server to minimize the risk of exploitation.

Fix

Improper Authorization

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2020-02853
CVE-2020-1745
GHSA-GV2W-88HX-8M9R
RHSA-2020:0813
RHSA-2020:0962
RHSA-2020:2058
RHSA-2020:2059
RHSA-2020:2060
RHSA-2020:2511
RHSA-2020:2512
RHSA-2020:2513
RHSA-2024:5856

Affected Products

Undertow