V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2024-1459
DEB
Medium

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an H…

CVSS
5.3
Medium
EPSS
0.10
p93
Published
2024-01-01
Updated
2024-01-01
Description

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

Tags · CWE
Pre-auth
CWE-24
Affected products
Eap7-activemq-artemisEap7-activemq-artemisEap7-activemq-artemisEap7-apache-cxfEap7-apache-cxfEap7-apache-cxfEap7-eclipse-jgitEap7-eclipse-jgitEap7-eclipse-jgitEap7-elytron-webEap7-elytron-webEap7-elytron-webEap7-hal-consoleEap7-hal-consoleEap7-hal-consoleEap7-hibernateEap7-hibernateEap7-hibernateEap7-infinispanEap7-infinispan
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Timeline
2024-01-01
Published
2024-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.101 · p93
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected software
ProductVendorStatus
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-activemq-artemisTracked
eap7-apache-cxfTracked
eap7-apache-cxfTracked
eap7-apache-cxfTracked
eap7-eclipse-jgitTracked
eap7-eclipse-jgitTracked
eap7-eclipse-jgitTracked
eap7-elytron-webTracked
eap7-elytron-webTracked
eap7-elytron-webTracked
eap7-hal-consoleTracked
eap7-hal-consoleTracked
eap7-hal-consoleTracked
eap7-hibernateTracked
eap7-hibernateTracked
eap7-hibernateTracked
eap7-infinispanTracked
eap7-infinispanTracked
Source databases
DEB
CVE
RED
UBU