Uploaded image for project: 'Undertow'
  1. Undertow
  2. UNDERTOW-2339

CVE-2024-1459 Directory traversal vulnerability when accessed via proxy

XMLWordPrintable

    In a setup when Undertow is accessed via a proxy, and the proxy is configured to redirect to some non-root request path on the EAP server, a client can break out of the configured request path by using "/..;/" string in the request URI path.

          thofman Tomas Hofman
          thofman Tomas Hofman
          Alessio Soldano, Bartosz Baranowski, Brad Maxwell, Brian Stansberry, Carlo de Wolf, Chess Hazlett, Daniel Kreling, Darran Lofthouse, Farah Juma, Ilia Vassilev, Ingo Weiss, Lin Gao, Martin Stefanko, Martin Svehla, Michaela Osmerova, Miroslav Sochurek, Neil Wallace, Paramvir Jindal, Peter Mackay, Radovan Stancel, Stefano Maestri, Tom Jenkinson, Vladimir Dosoudil
          Votes:
          0 Vote for this issue
          Watchers:
          3 Start watching this issue

            Created:
            Updated:
            Resolved: