cbcvebase.
CVE-2014-7816
published 2014-12-01

CVE-2014-7816: Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows…

medium5CVSS 3.1
AVNACLAuNCPINAN
EXPLOIT
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianundertow
redhatundertow<= 1.0.16
redhatundertow<= 1.1.0
redhatundertow<= 1.2.0