CVE-2020-1757

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
21/04/2020
Last modified:
30/04/2020

Description

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* 2.1.0 (excluding)
cpe:2.3:a:redhat:undertow:2.0.0:sp1:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.25:sp1:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.26:sp3:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.28:sp1:*:*:*:*:*:*
cpe:2.3:a:redhat:undertow:2.0.28:sp2:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools