CVE-2020-1757
published 2020-04-21CVE-2020-1757: A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final…
PriorityP345high8.1CVSS 3.1
AVNACLPRLUINSUCHIHAN
EPSS
1.58%
72.8th percentile
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | undertow | < undertow 2.1.0-1 (forky) | undertow 2.1.0-1 (forky) |
| red_hat | undertow | — | — |
| red_hat | undertow | — | — |
| redhat | jboss_data_grid | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
| redhat | jboss_fuse | — | — |
| redhat | jboss_fuse | — | — |
| redhat | single_sign-on | — | — |
| redhat | undertow | < 2.1.0 | 2.1.0 |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | — | — |
| redhat | undertow | >= 0 < 2.1.0-1 | 2.1.0-1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:N
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2020-1757: undertow - A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1...
vendor_debian·2020·CVSS 8.1
CVE-2020-1757 [HIGH] CVE-2020-1757: undertow - A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1...
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
Scope: local
forky: resolved (fixed in 2.1.0-1)
sid: resolved (fixed in 2.1.0-1)
Red Hat
undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass
vendor_redhat·2018-12-19·CVSS 8.1
CVE-2020-1757 [HIGH] CWE-41 undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass
undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
A flaw was found in Undertow, where the servlet container causes the servletPath to normalize incorrectly by truncating the path after the semicolon. The flaw may lead to application mapping, resulting in a security bypass.
Mitigation: The issue can be mitigated by configuring UrlPathHelper to ignore the servletPath via se
OSV
Improper Input Validation in Undertow
osv·2022-05-24
CVE-2020-1757 [HIGH] Improper Input Validation in Undertow
Improper Input Validation in Undertow
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
GHSA
Improper Input Validation in Undertow
ghsa·2022-05-24
CVE-2020-1757 [HIGH] CWE-20 Improper Input Validation in Undertow
Improper Input Validation in Undertow
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
OSV
CVE-2020-1757: A flaw was found in all undertow-2
osv·2020-04-21·CVSS 8.1
CVE-2020-1757 [HIGH] CVE-2020-1757: A flaw was found in all undertow-2
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27753 ImageMagick: memory leaks in AcquireMagickMemory function
bugzilla·2020-11-03·CVSS 5.5
CVE-2020-27753 [MEDIUM] CVE-2020-27753 ImageMagick: memory leaks in AcquireMagickMemory function
CVE-2020-27753 ImageMagick: memory leaks in AcquireMagickMemory function
In ImageMagick, there are memory leaks detected in AcquireMagickMemory.
Reference:
https://github.com/ImageMagick/ImageMagick/issues/1757
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/bb3acad195de95db86c7509d8072db01890470e0
Discussion:
Acknowledgments:
Name: Suhwan Song (Seoul National University)
---
Flaw summary:
There are several memory leaks in the MIFF coder in /coders/miff.c due to improper image depth values, which can be triggered by a specially crafted input file. These leaks could potentially lead to an impact to application availability or cause a denial of service. It was originally reported that the issues were in `AcquireMagickMemory()` because that is where LeakSanitizer de
Bugzilla
CVE-2020-1757 undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass
bugzilla·2019-09-17·CVSS 8.1
CVE-2020-1757 [HIGH] CVE-2020-1757 undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass
CVE-2020-1757 undertow: servletPath is normalized incorrectly leading to dangerous application mapping which could result in security bypass
The servletPath is normalized by the Servlet container, and truncated after the semicolon, leading to a partial servletPath. Leading to a full path "/api/public/aa/secret" and servletPath "/api/public/aa" leading to application mapping "/secret". This can lead to a security bypass depending on where and how URL-based security is applied.
Discussion:
Acknowledgments:
Name: Fedorov Oleksii (LINE Corporation), Keitaro Yamazaki (LINE Corporation), Shiga Ryota (LINE Corporation)
---
Hi
Ist here any more information available on this issue? Is it reported upstream and fixed? I'm interested to track this issue in other downstreams (in my case Debian)
2020-04-21
Published