ZeroHour

CVE-2020-1757

CVSS 3.1
8.1 high
EPSS
2%p74
Published
()
Modified
Description

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

Vendors
redhat
Products
undertow, jboss data grid, jboss enterprise application platform, jboss fuse, openshift application runtimes, single sign-on
Weakness
CWE-20, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.