Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Package
Affected versions
= 7.1.0.GA
Patched versions
7.1.1.GA
Description
Published by the National Vulnerability Database
Jan 24, 2018
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 30, 2022
Last updated
Jan 27, 2023
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
References