Lucene search

K
osvGoogleOSV:GHSA-H6P6-FC4W-CQHX
HistoryMay 17, 2022 - 4:15 a.m.

Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow

2022-05-1704:15:16
Google
osv.dev
14
directory traversal
jboss undertow
windows
arbitrary files

EPSS

0.046

Percentile

92.6%

Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a … (dot dot) in a resource URI.