CVE-2018-1048
—CVSS 3.1
7.5 high
EPSS
2%p74
Published
()
Modified
Description
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
- Vendors
- redhat
- Products
- jboss enterprise application platform
- Weakness
- CWE-22, CWE-116
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.