First published: Mon Oct 27 2014(Updated: )
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Undertow | <=1.0.16 | |
Redhat Undertow | <=1.1.0 | |
Redhat Undertow | <=1.2.0 | |
Microsoft Windows | ||
redhat/undertow | <1.0.17. | 1.0.17. |
redhat/undertow | <1.2.0. | 1.2.0. |
redhat/undertow | <1.1.0. | 1.1.0. |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.