CVE-2018-1047: Input Validation
A flaw was found in Wildfly 9.x. A patch traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
Upstrea bug:
https://issues.jboss.org/browse/WFLY-9620
References:
https://developer.jboss.org/thread/276826
Other sources
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1047?
CVE-2018-1047 has been classified as a medium severity vulnerability due to the potential for information disclosure.
How do I fix CVE-2018-1047?
To mitigate CVE-2018-1047, upgrade to a patched version of Red Hat JBoss WildFly Application Server, specifically versions 9.0.1 or later.
Which versions of Red Hat JBoss WildFly Application Server are affected by CVE-2018-1047?
Affected versions of Red Hat JBoss WildFly Application Server include 9.0.0, 9.0.0-alpha1, 9.0.0-beta1, 9.0.0-beta2, 9.0.0-cr1, 9.0.0-cr2, and specific versions of 10.0.0.
What type of vulnerability is CVE-2018-1047?
CVE-2018-1047 is a path traversal vulnerability that could lead to unauthorized access to arbitrary local files on the server.
Is CVE-2018-1047 exploitable remotely?
Yes, CVE-2018-1047 can be exploited remotely, allowing attackers to disclose sensitive information.