Total vulnerabilities in the database
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.
Software | From | Fixed in |
---|---|---|
redhat / undertow | - | 1.0.16.x |
redhat / undertow | - | 1.1.0.x |
redhat / undertow | - | 1.2.0.x |
![]() |
1.0.0 | 1.0.17 |
![]() |
1.1.0.Beta1 | 1.1.0.CR5 |
![]() |
1.2.0.Beta1 | 1.2.0.Beta3 |