CVE-2018-1048
published 2018-01-24CVE-2018-1048: It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash /…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
1.59%
72.9th percentile
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 1.4.22-1 (forky) | undertow 1.4.22-1 (forky) |
| red_hat_inc | undertow_as_shipped_in_jboss_eap_7.1.0.ga | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | >= 0 < 1.4.22-1 | 1.4.22-1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
osv·2022-05-13
CVE-2018-1048 [HIGH] Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
ghsa·2022-05-13
CVE-2018-1048 [HIGH] CWE-22 Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
Improper Limitation of a Pathname to a Restricted Directory in Jboss EAP Undertow
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
OSV
CVE-2018-1048: It was found that the AJP connector in undertow, as shipped in Jboss EAP 7
osv·2018-01-24·CVSS 7.5
CVE-2018-1048 [HIGH] CVE-2018-1048: It was found that the AJP connector in undertow, as shipped in Jboss EAP 7
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Red Hat
undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
vendor_redhat·2018-01-15·CVSS 7.5
CVE-2018-1048 [HIGH] CWE-22 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
It was found that the AJP connector in undertow does not use the ALLOW_ENCODED_SLASH option and thus allows the slash and anti-slash characters encoded in a URL. This may lead to path traversal and result in the information disclosure of arbitrary local files.
Package: Karaf (Red Hat Fuse 7) - Affected
Package: Karaf (Red Hat JBoss Fuse 6) - Will not fix
Package: undetow (Red Hat JBoss Fuse Integration Servic
Debian
CVE-2018-1048: undertow - It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.G...
vendor_debian·2018·CVSS 7.5
CVE-2018-1048 [HIGH] CVE-2018-1048: undertow - It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.G...
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Scope: local
forky: resolved (fixed in 1.4.22-1)
sid: resolved (fixed in 1.4.22-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-19044 keepalived: Improper pathname validation allows for overwrite of arbitrary filenames via symlinks
bugzilla·2018-11-21·CVSS 4.7
CVE-2018-19044 [MEDIUM] CVE-2018-19044 keepalived: Improper pathname validation allows for overwrite of arbitrary filenames via symlinks
CVE-2018-19044 keepalived: Improper pathname validation allows for overwrite of arbitrary filenames via symlinks
keepalived before version 2.0.9 didn't check for pathnames with symlinks when writing data to a temporary file upon a call to PrintData or PrintStats. This allowed local users to overwrite arbitrary files if fs.protected_symlinks is set to 0, as demonstrated by a symlink from /tmp/keepalived.data or /tmp/keepalived.stats to /etc/passwd.
Upstream Patch:
https://github.com/acassen/keepalived/commit/04f2d32871bb3b11d7dc024039952f2fe2750306
Upstream Issue:
https://github.com/acassen/keepalived/issues/1048
Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1015141
Discussion:
Created keepalived tracking bugs for this issue:
Affects: fedora-all [bug 1651864]
---
State
Bugzilla
CVE-2018-19046 keepalived: Insecure use of temporary files allows attackers read sensitive information from pre-existing files
bugzilla·2018-11-21·CVSS 4.7
CVE-2018-19046 [MEDIUM] CVE-2018-19046 keepalived: Insecure use of temporary files allows attackers read sensitive information from pre-existing files
CVE-2018-19046 keepalived: Insecure use of temporary files allows attackers read sensitive information from pre-existing files
keepalived before version 2.0.10 didn't check for existing plain files when writing data to a temporary file upon a call to PrintData or PrintStats. If a local attacker had previously created a file with the expected name (e.g., /tmp/keepalived.data or /tmp/keepalived.stats), with read access for the attacker and write access for the keepalived process, then this potentially leaked sensitive information.
Upstream Issue:
https://github.com/acassen/keepalived/issues/1048
Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1015141
Discussion:
Created keepalived tracking bugs for this issue:
Affects: fedora-all [bug 1651870]
---
Upstream fixes:
https://gi
Bugzilla
CVE-2018-19045 keepalived: Insecure permissions when creating new temporary files allows for leaking of sensitive data
bugzilla·2018-11-21·CVSS 7.5
CVE-2018-19045 [HIGH] CVE-2018-19045 keepalived: Insecure permissions when creating new temporary files allows for leaking of sensitive data
CVE-2018-19045 keepalived: Insecure permissions when creating new temporary files allows for leaking of sensitive data
keepalived before version 2.0.9 used mode 0666 when creating new temporary files upon a call to PrintData or PrintStats, potentially leaking sensitive information.
Upstream Patch:
https://github.com/acassen/keepalived/commit/5241e4d7b177d0b6f073cfc9ed5444bf51ec89d6
https://github.com/acassen/keepalived/commit/c6247a9ef2c7b33244ab1d3aa5d629ec49f0a067
Upstream Issue:
https://github.com/acassen/keepalived/issues/1048
Reference:
https://bugzilla.suse.com/show_bug.cgi?id=1015141
Discussion:
Created keepalived tracking bugs for this issue:
Affects: fedora-all [bug 1651868]
---
Statement:
This issue did not affect the versions of keepalived as shipped with Red Hat
Bugzilla
CVE-2018-1048 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
bugzilla·2018-01-15·CVSS 7.5
CVE-2018-1048 [HIGH] CVE-2018-1048 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
CVE-2018-1048 undertow: ALLOW_ENCODED_SLASH option not taken into account in the AjpRequestParser
It was found that the AJP connector in undertow does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2018:0478 https://access.redhat.com/errata/RHSA-2018:0478
---
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform 7.1 for RHEL 7
Via RHSA-2018:0480 https://access.redhat.com/errata/RHSA-2018:0480
---
This issue has been addressed in the following produ
https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://bugzilla.redhat.com/show_bug.cgi?id=1534343https://access.redhat.com/errata/RHSA-2018:0478https://access.redhat.com/errata/RHSA-2018:0479https://access.redhat.com/errata/RHSA-2018:0480https://access.redhat.com/errata/RHSA-2018:0481https://bugzilla.redhat.com/show_bug.cgi?id=1534343
2018-01-24
Published