5.3
CVSSv3

CVE-2024-1459

Published: 12/02/2024 Updated: 27/02/2024
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A path traversal vulnerability was found in Undertow. This issue may allow a remote malicious user to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat undertow -

Vendor Advisories

Debian Bug report logs - #1068816 undertow: CVE-2024-1459 Package: src:undertow; Maintainer for src:undertow is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Thu, 11 Apr 2024 15:39:04 UTC Severity: grave Tags: security, upstream Re ...