Red Hat Undertow vulnerabilities
7 known vulnerabilities affecting red_hat/undertow.
Total CVEs
7
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2020-10719MEDIUMCVSS 6.5vVersions before 2.1.1.Final2020-05-26
CVE-2020-10719 [MEDIUM] CWE-444 CVE-2020-10719: A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTT
A flaw was found in Undertow in versions before 2.1.1.Final, regarding the processing of invalid HTTP requests with large chunk sizes. This flaw allows an attacker to take advantage of HTTP request smuggling.
cvelistv5nvd
CVE-2020-1757HIGHCVSS 8.1vall undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1vall undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final2020-04-21
CVE-2020-1757 [HIGH] CWE-20 CVE-2020-1757: A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
cvelistv5nvd
CVE-2019-14888HIGHCVSS 7.5vAll versions before 2.0.28.SP12020-01-23
CVE-2019-14888 [HIGH] CWE-400 CVE-2019-14888: A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening o
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
cvelistv5nvd
CVE-2019-3888CRITICALCVSS 9.8v2.0.212019-06-12
CVE-2019-3888 [CRITICAL] CWE-532 CVE-2019-3888: A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain tex
A vulnerability was found in Undertow web server before 2.0.21. An information exposure of plain text credentials through log files because Connectors.executeRootHandler:402 logs the HttpServerExchange object at ERROR level using UndertowLogger.REQUEST_LOGGER.undertowRequestFailed(t, exchange)
cvelistv5nvd
CVE-2018-14642MEDIUMCVSS 5.3vn/a2018-09-18
CVE-2018-14642 [MEDIUM] CWE-200 CVE-2018-14642: An information leak vulnerability was found in Undertow. If all headers are not written out in the f
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
cvelistv5nvd
CVE-2018-1114MEDIUMCVSS 6.5vn/a2018-09-11
CVE-2018-1114 [MEDIUM] CWE-400 CVE-2018-1114: It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when th
It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.
cvelistv5nvd
CVE-2017-12165HIGHCVSS 7.5v1.4.17v1.3.31+1 more2018-07-27
CVE-2017-12165 [LOW] CWE-444 CVE-2017-12165: It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with
It was discovered that Undertow before 1.4.17, 1.3.31 and 2.0.0 processes http request headers with unusual whitespaces which can cause possible http request smuggling.
cvelistv5nvd