undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
| Software | From | Fixed in |
|---|---|---|
| redhat / undertow | - | 2.0.23 |
| redhat / jboss_enterprise_application_platform | 7.0.0 | 7.0.0.x |
| redhat / single_sign-on | 7.0 | 7.0.x |
| redhat / openshift_application_runtimes | 1.0 | 1.0.x |
| redhat / jboss_enterprise_application_platform | 7.2 | 7.2.x |
| redhat / jboss_enterprise_application_platform | 7.3 | 7.3.x |
| redhat / jboss_enterprise_application_platform | 7.4 | 7.4.x |
| redhat / single_sign-on | 7.3 | 7.3.x |
io.undertow / undertow-core
|
- | 2.0.23 |