CVE-2020-1757
Published: Apr 21, 2020
Modified: Aug 4, 2024
CVSS v3.0
8.1
Description
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
| Vendor | Product | Versions |
|---|---|---|
Red Hat | undertow | affected all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1affected all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final |
CVSS v3.0 Details
CVSS v3.0 Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now