CVE-2019-10184

HIGH7.5EPSS 1.5%

Undertow Missing Authorization when requesting a protected directory without trailing slash

發布日:2019/8/1修改日:2026/4/28
也稱為:DEBIAN-CVE-2019-10184

描述

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(17)