A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| io.undertow:undertow-core(Maven) | 0 | 2.2.31.Final | N/A |
| io.undertow:undertow-core(Maven) | 2.3.0.Alpha1 | 2.3.12.Final | N/A |
CVSS Metrics