CVE-2014-7816

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
01/12/2014
Last modified:
12/04/2025

Description

Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* 1.0.16 (including)
cpe:2.3:a:redhat:undertow:*:cr4:*:*:*:*:*:* 1.1.0 (including)
cpe:2.3:a:redhat:undertow:*:beta2:*:*:*:*:*:* 1.2.0 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*