CVE-2018-1048 PUBLISHED

It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.

EPSS 0.51% · 66.2th percentile

Risk Scores

EPSS Score
0.51%
66.2th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSundertow1.4.23-3, 0, 1.4.20-1
Ubuntu:16.04:LTSundertow1.3.4-1, 1.3.5-1, 1.3.7-1
Ubuntu:25.10undertow2.3.18-2, 0, 2.3.18-1
Ubuntu:22.04:LTSundertow2.2.16-1, 2.2.13-1, 2.2.14-1
Ubuntu:24.04:LTSundertow2.3.8-2, 0
Ubuntu:20.04:LTSundertow2.0.27-1, 2.0.29-1, 0

Timeline

References

Open in Interactive Console →