CVE-2018-14642
Summary
| CVE | CVE-2018-14642 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-09-18 13:29:00 UTC |
| Updated | 2020-12-08 15:50:00 UTC |
| Description | An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 6.0 | All | All | All |
| Operating System | Redhat | Enterprise Linux | 7.0 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.3 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.1 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.2 | All | All | All |
| Application | Redhat | Jboss Enterprise Application Platform | 7.3 | All | All | All |
| Application | Redhat | Undertow | - | All | All | All |
| Application | Redhat | Undertow | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | Vendor Advisory |
| 1628702 – (CVE-2018-14642) CVE-2018-14642 undertow: Infoleak in some circumstances where Undertow can serve data from a random buffer | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.