CVE-2015-3198: Infoleak
A flaw was reported in the Undertow module of WildFly that leaks the source code of a JSP page when a trailing slash (/) is added to the end of its URL.
This issue did not affect any versions of Red Hat JBoss Enterprise Application Platform because this flaw only affects the Undertow web module; JBoss EAP uses JBoss Web.
Other sources
The Undertow module of WildFly 9.x before 9.0.0.CR2 and 10.x before 10.0.0.Alpha1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.
— MITRE
The Undertow module of WildFly versions 8.1.0.Final, 8.2.0.Final, 9.0.0.CR1 allows remote attackers to obtain the source code of a JSP page via a "/" at the end of a URL.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3198?
CVE-2015-3198 has a moderate severity level as it can expose source code inadvertently.
How do I fix CVE-2015-3198?
To address CVE-2015-3198, upgrade to WildFly version 9.0.0.CR2 or later.
Which versions are affected by CVE-2015-3198?
CVE-2015-3198 affects WildFly versions from 8.1.0.Final up to 9.0.0.CR1.
Does CVE-2015-3198 affect Red Hat JBoss Enterprise Application Platform?
No, CVE-2015-3198 does not affect any versions of Red Hat JBoss Enterprise Application Platform.
What type of vulnerability is CVE-2015-3198?
CVE-2015-3198 is a source code disclosure vulnerability in the Undertow module of WildFly.