JBoss Undertow CVE-2014-7816 Directory Traversal Vulnerability
BID:71328
Info
JBoss Undertow CVE-2014-7816 Directory Traversal Vulnerability
| Bugtraq ID: | 71328 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-7816 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 26 2014 12:00AM |
| Updated: | Nov 26 2014 12:00AM |
| Credit: | Roberto Soares of Conviso Application Security. |
| Vulnerable: |
JBoss Community Undertow 1.2 Beta1 |
| Not Vulnerable: |
JBoss Community Undertow 1.2 Beta3 JBoss Community Undertow 1.1 CR5 JBoss Community Undertow 1.0.17 Final |
Discussion
JBoss Undertow CVE-2014-7816 Directory Traversal Vulnerability
JBoss Undertow is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
Undertow 1.2.0 Beta1 is vulnerable.
JBoss Undertow is prone to a directory-traversal vulnerability because it fails to sufficiently sanitize user-supplied input.
Exploiting this issue can allow an attacker to obtain sensitive information that could aid in further attacks.
Undertow 1.2.0 Beta1 is vulnerable.
Exploit / POC
JBoss Undertow CVE-2014-7816 Directory Traversal Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
JBoss Undertow CVE-2014-7816 Directory Traversal Vulnerability
References:
References:
- CVE-2014-7816 - Undertow Directory Traversal (Roberto Soares)
- Undertow - Homepage (JBoss Community)
- Undertow: Information disclosure via directory traversal (Roberto Soares)