It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-4818 | It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files. |
Github GHSA |
GHSA-prfw-3qx6-g9xr | Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 23 Aug 2024 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T03:44:11.828Z
Reserved: 2017-12-04T00:00:00.000Z
Link: CVE-2018-1048
No data.
Status : Modified
Published: 2018-01-24T23:29:00.607
Modified: 2024-11-21T03:59:03.983
Link: CVE-2018-1048
OpenCVE Enrichment
No data.
EUVD
Github GHSA