It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
History

Fri, 23 Aug 2024 05:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:7::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.1::el7

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2018-01-24T23:00:00Z

Updated: 2024-08-05T03:44:11.828Z

Reserved: 2017-12-04T00:00:00

Link: CVE-2018-1048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2018-01-24T23:29:00.607

Modified: 2023-02-03T02:19:53.263

Link: CVE-2018-1048

cve-icon Redhat

Severity : Moderate

Publid Date: 2018-01-15T00:00:00Z

Links: CVE-2018-1048 - Bugzilla