CVE-2018-14642
Exposure of Sensitive Information to an Unauthorized Actor in Undertow
5.3
MEDIUM
CVSS 3.1
EPSS 2.1%
描述
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
如何修補 CVE-2018-14642
要修補 CVE-2018-14642,請將受影響套件升級到下列已修補版本。
- —升級至 2.0.23-1 或更新版本
- —升級至 2.0.19.FINAL 或更新版本
CVE-2018-14642 正在被利用嗎?
低 — EPSS 為 2.1%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 2.0.23-1
- from 0, < 2.0.19.FINAL
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |