CVE-2018-14642
published 2018-09-18CVE-2018-14642: An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.11%
79.7th percentile
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.0.23-1 (forky) | undertow 2.0.23-1 (forky) |
| red_hat | undertow | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | undertow | >= 0 < 2.0.23-1 | 2.0.23-1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
osv·2022-05-13
CVE-2018-14642 [MEDIUM] Exposure of Sensitive Information to an Unauthorized Actor in Undertow
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
ghsa·2022-05-13
CVE-2018-14642 [MEDIUM] CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in Undertow
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
OSV
CVE-2018-14642: An information leak vulnerability was found in Undertow
osv·2018-09-18·CVSS 5.3
CVE-2018-14642 [MEDIUM] CVE-2018-14642: An information leak vulnerability was found in Undertow
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Red Hat
undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer
vendor_redhat·2018-09-14·CVSS 5.3
CVE-2018-14642 [MEDIUM] CWE-200 undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer
undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Package: undertow (Red Hat Fuse 7) - Not affected
Package: undertow (Red Hat JBoss Data Grid 7) - Not affected
Package: jbossweb (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: undertow (Red Hat JBoss Fuse 6) - Out of support scope
Package: undertow (Red Hat JBoss Fuse Integration Service 2) - Out of support scope
Package: undertow (Red Hat OpenShift Application Runtimes) - Affected
Debian
CVE-2018-14642: undertow - An information leak vulnerability was found in Undertow. If all headers are not ...
vendor_debian·2018·CVSS 5.3
CVE-2018-14642 [MEDIUM] CVE-2018-14642: undertow - An information leak vulnerability was found in Undertow. If all headers are not ...
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Scope: local
forky: resolved (fixed in 2.0.23-1)
sid: resolved (fixed in 2.0.23-1)
No detection rules found.
No public exploits indexed.
arXiv
Tracking Patches for Open Source Software Vulnerabilities
arxiv_fulltext·2023-09-30
Tracking Patches for Open Source Software Vulnerabilities
Tracking Patches for Open Source Software Vulnerabilities
Congying Xu
Also with Shanghai Key Laboratory of Data Science, and Shanghai Collaborative Innovation Center of Intelligent Visual Computing.
School of Computer Science
Fudan University
Shanghai
China
Bihuan Chen
[1]
Bihuan Chen is the corresponding author.
School of Computer Science
Fudan University
Shanghai
China
Chenhao Lu
[1]
School of Computer Science
Fudan University
Shanghai
China
Kaifeng Huang
[1]
School of Computer Science
Fudan University
Shanghai
China
Xin Peng
[1]
School of Computer Science
Fudan University
Shanghai
China
Yang Liu
School of Computer Science and Engineering
Nanyang Technological University
Singapore
## Abstract
Open source software (OSS) vulnerabilities threaten the security of software syste
Bugzilla
CVE-2018-14642 undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer
bugzilla·2018-09-13·CVSS 5.3
CVE-2018-14642 [MEDIUM] CVE-2018-14642 undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer
CVE-2018-14642 undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer
In some circumstances Undertow can serve data from a random ByteBuffer, this is due to an incomplete fix for UNDERTOW-438.
Basically if all the headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Upstream bug:
https://issues.jboss.org/browse/JBEAP-15428
Upstream patch:
https://github.com/jbossas/redhat-undertow/commit/e65ad5b410f95b166ff04f876e22f873e9b4ce62
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Enterprise Application Platform
Via RHSA-2019:0362 https://access.redhat.co
https://access.redhat.com/errata/RHSA-2019:0362https://access.redhat.com/errata/RHSA-2019:0364https://access.redhat.com/errata/RHSA-2019:0365https://access.redhat.com/errata/RHSA-2019:0380https://access.redhat.com/errata/RHSA-2019:1106https://access.redhat.com/errata/RHSA-2019:1107https://access.redhat.com/errata/RHSA-2019:1108https://access.redhat.com/errata/RHSA-2019:1140https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14642https://access.redhat.com/errata/RHSA-2019:0362https://access.redhat.com/errata/RHSA-2019:0364https://access.redhat.com/errata/RHSA-2019:0365https://access.redhat.com/errata/RHSA-2019:0380https://access.redhat.com/errata/RHSA-2019:1106https://access.redhat.com/errata/RHSA-2019:1107https://access.redhat.com/errata/RHSA-2019:1108https://access.redhat.com/errata/RHSA-2019:1140https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14642
2018-09-18
Published