A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.
References
Configurations
History
22 Nov 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
21 Nov 2024, 08:50
Type | Values Removed | Values Added |
---|---|---|
References | () https://access.redhat.com/errata/RHSA-2024:1677 - | |
References | () https://access.redhat.com/errata/RHSA-2024:2763 - | |
References | () https://access.redhat.com/errata/RHSA-2024:2764 - | |
References | () https://access.redhat.com/security/cve/CVE-2024-1459 - Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2259475 - Issue Tracking |
21 Aug 2024, 08:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
15 May 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
08 May 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
27 Feb 2024, 16:55
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
First Time |
Redhat undertow
Redhat |
|
CPE | cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:* | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=2259475 - Issue Tracking | |
References | () https://access.redhat.com/security/cve/CVE-2024-1459 - Vendor Advisory |
12 Feb 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-12 21:15
Updated : 2024-11-22 12:15
NVD link : CVE-2024-1459
Mitre link : CVE-2024-1459
CVE.ORG link : CVE-2024-1459
JSON object : View
Products Affected
redhat
- undertow
CWE
CWE-24
Path Traversal: '../filedir'