CVE-2020-1757
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
21/04/2020
Last modified:
30/04/2020
Description
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
Impact
Base Score 3.x
8.10
Severity 3.x
HIGH
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* | 2.1.0 (excluding) | |
| cpe:2.3:a:redhat:undertow:2.0.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:undertow:2.0.25:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:undertow:2.0.26:sp3:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:undertow:2.0.28:sp1:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:undertow:2.0.28:sp2:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:jboss_data_grid:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:jboss_fuse:6.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:jboss_fuse:7.0.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



