Severity
5.5MEDIUM
EPSS
0.2%
top 60.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 24
Latest updateOct 19

Description

A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

🔴Vulnerability Details

4
OSV
Improper Input Validation in org.wildfly:wildfly-undertow2018-10-19
GHSA
Improper Input Validation in org.wildfly:wildfly-undertow2018-10-19
CVEList
CVE-2018-1047: A flaw was found in Wildfly 92018-01-24
OSV
CVE-2018-1047: A flaw was found in Wildfly 92018-01-24

📋Vendor Advisories

1
Red Hat
undertow: Path traversal in ServletResourceManager class2017-12-17

💬Community

5
Bugzilla
CVE-2018-14340 wireshark: Multiple dissectors could crash (wnpa-sec-2018-36)2018-07-23
Bugzilla
CVE-2018-14368 wireshark: Bazaar dissector infinite loop (wnpa-sec-2018-40)2018-07-23
Bugzilla
CVE-2018-14341 wireshark: DICOM dissector infinite loop (wnpa-sec-2018-39)2018-07-23
Bugzilla
CVE-2018-7418 wireshark: SIGCOMP dissector crash in packet-sigcomp.c2018-02-26
Bugzilla
CVE-2018-1047 undertow: Path traversal in ServletResourceManager class2017-12-21
CVE-2018-1047 (MEDIUM CVSS 5.5) | A flaw was found in Wildfly 9.x | cvebase.io