VDB
CVE-2021-3688
CVE-2021-3688
PUBLISHED
CVSS 9.100000381469727 CRITICAL
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
EPSS 0.56% · 44.3th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.56%
44.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| redhat | jboss_core_services_httpd | 0, 2.4.37, 2.4.37 |
| n/a | Red Hat JBCS HTTP Server | Fixed in jbcs-httpd-2.4.37.SP10 GA |
Timeline
- Aug 26, 2022 CVE Published
- Aug 27, 2022 EPSS Score
- Oct 12, 2022 EPSS Score
- Nov 27, 2022 EPSS Score
- Jan 12, 2023 EPSS Score
- Feb 27, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 15, 2023 EPSS Score
- May 31, 2023 EPSS Score
- Jul 16, 2023 EPSS Score
- Aug 31, 2023 EPSS Score
- Oct 16, 2023 EPSS Score