CVE-2018-1047
published 2018-01-24CVE-2018-1047: A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method…
PriorityP425medium5.5CVSS 3.0
AVLACLPRLUINSUCHINAN
EPSS
0.49%
38.8th percentile
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| red_hat_inc | wildfly | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_wildfly_application_server | — | — |
| redhat | jboss_wildfly_application_server | — | — |
| redhat | jboss_wildfly_application_server | — | — |
| redhat | jboss_wildfly_application_server | — | — |
| redhat | jboss_wildfly_application_server | — | — |
| redhat | jboss_wildfly_application_server | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: Path traversal in ServletResourceManager class
vendor_redhat·2017-12-17·CVSS 5.5
CVE-2018-1047 [MEDIUM] CWE-20 undertow: Path traversal in ServletResourceManager class
undertow: Path traversal in ServletResourceManager class
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
A path traversal vulnerability was discovered in Undertow's org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method. This could lead to information disclosure of arbitrary local files.
Package: wildfly-undertow (JBoss Developer Studio 10) - Out of support scope
Package: undertow (Red Hat Fuse 7) - Affected
Package: wildfly-undertow (Red Hat JBoss Data Grid 7) - Not affected
Package: undertow (Red Hat JBoss Fuse 6) - Will not fix
Package: undertow (Red Hat JBoss Fuse Integration Se
OSV
Improper Input Validation in org.wildfly:wildfly-undertow
osv·2018-10-19
CVE-2018-1047 [MEDIUM] Improper Input Validation in org.wildfly:wildfly-undertow
Improper Input Validation in org.wildfly:wildfly-undertow
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
GHSA
Improper Input Validation in org.wildfly:wildfly-undertow
ghsa·2018-10-19
CVE-2018-1047 [MEDIUM] CWE-20 Improper Input Validation in org.wildfly:wildfly-undertow
Improper Input Validation in org.wildfly:wildfly-undertow
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
OSV
CVE-2018-1047: A flaw was found in Wildfly 9
osv·2018-01-24·CVSS 5.5
CVE-2018-1047 [MEDIUM] CVE-2018-1047: A flaw was found in Wildfly 9
A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14340 [HIGH] CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)
It was found that dissectors that support zlib decompression could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14675
External References:
https://www.wireshark.org/security/wnpa-sec-2018-36.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/27561/2/epan/tvbuff_zlib.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further
Bugzilla
CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14368 [HIGH] CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)
CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)
It was found that Bazaar dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14841
External References:
https://www.wireshark.org/security/wnpa-sec-2018-40.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/28228/2/epan/dissectors/packet-bzr.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further updates for indiv
Bugzilla
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
bugzilla·2018-07-23·CVSS 7.5
CVE-2018-14341 [HIGH] CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)
It was found that DICOM dissector could crash by injecting a malformed packet onto the wire or by convincing someone to read a malformed packet trace file.
Upstream bug(s):
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14742
External References:
https://www.wireshark.org/security/wnpa-sec-2018-39.html
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1607334]
---
Upstream patch:
https://code.wireshark.org/review/#/c/27853/2/epan/dissectors/packet-dcm.c
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed. Further updates for individ
Bugzilla
CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c
bugzilla·2018-02-26·CVSS 7.5
CVE-2018-7418 [HIGH] CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c
CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c
A flaw was found in Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the SIGCOMP dissector could crash. This was addressed in epan/dissectors/packet-sigcomp.c by correcting the extraction of the length value.
External References:
https://www.wireshark.org/security/wnpa-sec-2018-13.html
https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=14410
Upstream Patch:
https://code.wireshark.org/review/gitweb?p=wireshark.git;a=commit;h=29d920b8309905
Discussion:
Created wireshark tracking bugs for this issue:
Affects: fedora-all [bug 1549306]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1047 https://access.redhat.com/errata/RHSA-2020:1047
---
This bug is now closed.
Bugzilla
CVE-2018-1047 undertow: Path traversal in ServletResourceManager class
bugzilla·2017-12-21·CVSS 5.5
CVE-2018-1047 [MEDIUM] CVE-2018-1047 undertow: Path traversal in ServletResourceManager class
CVE-2018-1047 undertow: Path traversal in ServletResourceManager class
A flaw was found in Wildfly 9.x. A patch traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
Upstrea bug:
https://issues.jboss.org/browse/WFLY-9620
References:
https://developer.jboss.org/thread/276826
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 6
Via RHSA-2018:1248 https://access.redhat.com/errata/RHSA-2018:1248
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
Via RHSA-2018:1247 https://access.redhat.com/errata/RHSA-2018:12
https://access.redhat.com/errata/RHSA-2018:1247https://access.redhat.com/errata/RHSA-2018:1248https://access.redhat.com/errata/RHSA-2018:1249https://access.redhat.com/errata/RHSA-2018:1251https://access.redhat.com/errata/RHSA-2018:2938https://bugzilla.redhat.com/show_bug.cgi?id=1528361https://issues.jboss.org/browse/WFLY-9620https://access.redhat.com/errata/RHSA-2018:1247https://access.redhat.com/errata/RHSA-2018:1248https://access.redhat.com/errata/RHSA-2018:1249https://access.redhat.com/errata/RHSA-2018:1251https://access.redhat.com/errata/RHSA-2018:2938https://bugzilla.redhat.com/show_bug.cgi?id=1528361https://issues.jboss.org/browse/WFLY-9620
2018-01-24
Published