CVE-2020-1757 PUBLISHED

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

EPSS 0.46% · 64.1th percentile

Risk Scores

EPSS Score
0.46%
64.1th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSundertow0, 2.3.8-2
Ubuntu:18.04:LTSundertow1.4.20-1, 1.4.23-1, 0
Ubuntu:22.04:LTSundertow2.2.13-1, 2.2.14-1, 0
Ubuntu:16.04:LTSundertow1.3.4-1, 1.3.11-1, 1.3.16-1
Ubuntu:25.10undertow2.3.18-2, 0, 2.3.18-1
Ubuntu:20.04:LTSundertow2.0.27-1, 2.0.23-1, 0

Timeline

References

Open in Interactive Console →