Undertow-Io Undertow vulnerabilities
2 known vulnerabilities affecting undertow-io/undertow.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2020-1745CRITICALCVSS 9.8≤ 2.0.29.Final2020-04-28
CVE-2020-1745 [HIGH] CWE-285 CVE-2020-1745: A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configurati
A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server
cvelistv5nvd
CVE-2019-10184HIGHCVSS 7.5vfixed in 2.0.23.Final2019-07-25
CVE-2019-10184 [HIGH] CWE-862 CVE-2019-10184: undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have t
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
cvelistv5nvd