Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5930
HistoryMar 16, 2018 - 2:36 a.m.

Information Disclosure Through Authorization Bypass

2018-03-1602:36:22
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8

0.003 Low

EPSS

Percentile

68.8%

undertow-core is vulnerable to information disclosure attacks through authorization bypass. The vulnerability exists as undertow-core does not validate the uri attribute in the Authorization header, allowing a man-in-the-middle (MitM) attacker to provide a bogus uri and accessing other content on the server.