ZeroHour

CVE-2019-10184

CVSS 3.1
7.5 high
EPSS
3%p88
Published
()
Modified
Description

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

Vendors
redhatnetapp
Products
undertow, jboss data grid, jboss enterprise application platform, openshift application runtimes, single sign-on, active iq unified manager
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.