CVE-2018-1048
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.59%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.59% probability · 74th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-116
- Affected
- redhat/jboss enterprise application platform
- Source
- secalert@redhat.com
References
- https://access.redhat.com/errata/RHSA-2018:0478Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0479Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0480Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0481Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1534343Issue Tracking, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0478Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0479Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0480Vendor Advisory
- https://access.redhat.com/errata/RHSA-2018:0481Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1534343Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.