ZeroHour

CVE-2018-14642

CVSS 3.1
5.3 medium
EPSS
2%p81
Published
()
Modified
Description

An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.

Vendors
redhat
Products
undertow, jboss enterprise application platform
Weakness
CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.