CVE-2014-7816
published 2014-12-01CVE-2014-7816: Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows…
medium5CVSS 3.1
AVNACLAuNCPINAN
EXPLOIT
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | — | — |
| redhat | undertow | <= 1.0.16 | — |
| redhat | undertow | <= 1.1.0 | — |
| redhat | undertow | <= 1.2.0 | — |