First published: Mon Jan 22 2024(Updated: )
A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
maven/io.undertow:undertow-core | >=2.3.0.Alpha1<2.3.12.Final | 2.3.12.Final |
maven/io.undertow:undertow-core | <2.2.31.Final | 2.2.31.Final |
Redhat Undertow | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.