It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Metrics
Affected Vendors & Products
References
History
Fri, 23 Aug 2024 05:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7 |
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2018-01-24T23:00:00Z
Updated: 2024-08-05T03:44:11.828Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2018-1048
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-01-24T23:29:00.607
Modified: 2024-11-21T03:59:03.983
Link: CVE-2018-1048
Redhat