CVE-2019-10184 PUBLISHED

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

EPSS 1.42% · 80.5th percentile

Risk Scores

EPSS Score
1.42%
80.5th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSundertow0, 2.3.8-2
Ubuntu:25.10undertow0, 2.3.18-1, 2.3.18-2
Ubuntu:16.04:LTSundertow1.3.16-1, 1.3.11-1, 0
Ubuntu:18.04:LTSundertow1.4.23-3, 0, 1.4.20-1
Ubuntu:20.04:LTSundertow0

Timeline

References

Open in Interactive Console →