org.jboss.eap:wildfly-undertow
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jboss.eap:wildfly-undertowpage 1 of 1
- CVE-2018-1048HIGHCVSS 7.5✓ Fixed in 7.1.1.GA2018-01-24
vulnerable: 7.1.0.GA
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and res…
- CVE-2018-1067MEDIUMCVSS 6.1✓ Fixed in 7.1.2.GA2018-05-21
In Undertow before versions 7.1.2.CR1, 7.1.2.GA it was found that the fix for CVE-2016-4993 was incomplete and Undertow web server is vulnerable to the injection of arbitrary HTTP headers, and also response splitting, due to insufficient s…
Check whether org.jboss.eap:wildfly-undertow is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jboss.eap:wildfly-undertow CVEs against the assets you own.
Start Free Scan →