First published: Thu Dec 21 2017(Updated: )
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Redhat Jboss Wildfly Application Server | =9.0.0 | |
Redhat Jboss Wildfly Application Server | =9.0.0-alpha1 | |
Redhat Jboss Wildfly Application Server | =9.0.0-beta1 | |
Redhat Jboss Wildfly Application Server | =9.0.0-beta2 | |
Redhat Jboss Wildfly Application Server | =9.0.0-cr1 | |
Redhat Jboss Wildfly Application Server | =9.0.0-cr2 | |
Redhat Jboss Wildfly Application Server | =9.0.1 | |
Redhat Jboss Wildfly Application Server | =9.0.2 | |
Redhat Jboss Wildfly Application Server | =10.0.0 | |
Redhat Jboss Wildfly Application Server | =10.0.0-alpha1 | |
Redhat Jboss Wildfly Application Server | =10.0.0-alpha2 | |
Redhat Jboss Wildfly Application Server | =10.0.0-alpha3 | |
Redhat Jboss Wildfly Application Server | =10.0.0-alpha4 | |
Redhat Jboss Wildfly Application Server | =10.0.0-alpha5 | |
Redhat Jboss Wildfly Application Server | =10.0.0-alpha6 | |
Redhat Jboss Wildfly Application Server | =10.0.0-beta1 | |
Redhat Jboss Wildfly Application Server | =10.0.0-beta2 | |
Redhat Jboss Wildfly Application Server | =10.0.0-cr1 | |
Redhat Jboss Wildfly Application Server | =10.0.0-cr2 | |
Redhat Jboss Wildfly Application Server | =10.0.0-cr3 | |
Redhat Jboss Wildfly Application Server | =10.0.0-cr4 | |
Redhat Jboss Wildfly Application Server | =10.0.0-cr5 | |
Redhat Jboss Wildfly Application Server | =10.1.0 | |
Redhat Jboss Wildfly Application Server | =10.1.0-cr1 | |
Redhat Jboss Wildfly Application Server | =11.0.0 | |
Redhat Jboss Wildfly Application Server | =11.0.0-alpha1 | |
Redhat Jboss Wildfly Application Server | =11.0.0-beta1 | |
Redhat Jboss Wildfly Application Server | =11.0.0-cr1 | |
Redhat Jboss Enterprise Application Platform | =7.1.0 | |
Redhat Enterprise Linux Server | =6.0 | |
Redhat Enterprise Linux Server | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.