CVE-2019-10184
published 2019-07-25CVE-2019-10184: undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
3.48%
87.8th percentile
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.0.23-1 (forky) | undertow 2.0.23-1 (forky) |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | openshift_application_runtimes | — | — |
| redhat | single_sign-on | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | < 2.0.23 | 2.0.23 |
| redhat | undertow | >= 0 < 2.0.23-1 | 2.0.23-1 |
| undertow-io | undertow | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
undertow: Information leak in requests for directories without trailing slashes
vendor_redhat·2019-07-24·CVSS 7.5
CVE-2019-10184 [HIGH] CWE-862 undertow: Information leak in requests for directories without trailing slashes
undertow: Information leak in requests for directories without trailing slashes
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
Package: jbossweb (Red Hat JBoss Enterprise Application Platform 6) - Out of support scope
Package: spring-boot (Red Hat JBoss Fuse 6) - Out of support scope
Package: undertow (Red Hat JBoss Fuse 6) - Out of support scope
Package: undertow (Red Hat OpenShift Application Runtimes) - Affected
Package: undertow (Red Hat Process Automation 7) - Not affected
Package: undertow (Red Hat support for Spring Boot) - Not affected
Debian
CVE-2019-10184: undertow - undertow before version 2.0.23.Final is vulnerable to an information leak issue....
vendor_debian·2019·CVSS 7.5
CVE-2019-10184 [HIGH] CVE-2019-10184: undertow - undertow before version 2.0.23.Final is vulnerable to an information leak issue....
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
Scope: local
forky: resolved (fixed in 2.0.23-1)
sid: resolved (fixed in 2.0.23-1)
GHSA
Undertow Missing Authorization when requesting a protected directory without trailing slash
ghsa·2019-08-01
CVE-2019-10184 [HIGH] CWE-862 Undertow Missing Authorization when requesting a protected directory without trailing slash
Undertow Missing Authorization when requesting a protected directory without trailing slash
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
OSV
Undertow Missing Authorization when requesting a protected directory without trailing slash
osv·2019-08-01
CVE-2019-10184 [HIGH] Undertow Missing Authorization when requesting a protected directory without trailing slash
Undertow Missing Authorization when requesting a protected directory without trailing slash
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
OSV
CVE-2019-10184: undertow before version 2
osv·2019-07-25·CVSS 7.5
CVE-2019-10184 [HIGH] CVE-2019-10184: undertow before version 2
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
No detection rules found.
No public exploits indexed.
https://access.redhat.com/errata/RHSA-2019:2935https://access.redhat.com/errata/RHSA-2019:2936https://access.redhat.com/errata/RHSA-2019:2937https://access.redhat.com/errata/RHSA-2019:2938https://access.redhat.com/errata/RHSA-2019:2998https://access.redhat.com/errata/RHSA-2019:3044https://access.redhat.com/errata/RHSA-2019:3045https://access.redhat.com/errata/RHSA-2019:3046https://access.redhat.com/errata/RHSA-2019:3050https://access.redhat.com/errata/RHSA-2020:0727https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10184https://github.com/undertow-io/undertow/pull/794https://security.netapp.com/advisory/ntap-20220210-0016/https://access.redhat.com/errata/RHSA-2019:2935https://access.redhat.com/errata/RHSA-2019:2936https://access.redhat.com/errata/RHSA-2019:2937https://access.redhat.com/errata/RHSA-2019:2938https://access.redhat.com/errata/RHSA-2019:2998https://access.redhat.com/errata/RHSA-2019:3044https://access.redhat.com/errata/RHSA-2019:3045https://access.redhat.com/errata/RHSA-2019:3046https://access.redhat.com/errata/RHSA-2019:3050https://access.redhat.com/errata/RHSA-2020:0727https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10184https://github.com/undertow-io/undertow/pull/794https://security.netapp.com/advisory/ntap-20220210-0016/
2019-07-25
Published