-
Bug
-
Resolution: Done
-
Minor
-
None
-
None
-
None
-
https://gitlab.cee.redhat.com/undertow-io/undertow/-/merge_requests/83, https://gitlab.cee.redhat.com/undertow-io/undertow/-/commit/bf03cd0882fc303a6e23af52cf246e49d352dd5b, https://gitlab.cee.redhat.com/undertow-io/undertow/-/commit/8ba927ff654db1097d58f84ed3e6b819e0c3e643, https://gitlab.cee.redhat.com/undertow-io/undertow/-/commit/abc5bd6f34b0662e6925e9bef8e16413f9ee2c96, https://github.com/undertow-io/undertow/pull/1556, https://github.com/undertow-io/undertow/pull/1559
In a setup when Undertow is accessed via a proxy, and the proxy is configured to redirect to some non-root request path on the EAP server, a client can break out of the configured request path by using "/..;/" string in the request URI path.
- is incorporated by
-
WFCORE-6709 CVE-2023-5379 CVE-2024-1459 CVE-2024-1635 Upgrade Undertow to 2.3.12.Final
- Resolved