{"id":"GHSA-h6p6-fc4w-cqhx","summary":"Improper Limitation of a Pathname to a Restricted Directory in JBoss Undertow","details":"Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.","aliases":["CVE-2014-7816"],"modified":"2024-12-07T05:40:06.129651Z","published":"2022-05-17T04:15:16Z","database_specific":{"nvd_published_at":"2014-12-01T15:59:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-06T21:05:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-7816"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1157478"},{"type":"WEB","url":"https://issues.jboss.org/browse/UNDERTOW-338"},{"type":"WEB","url":"https://issues.jboss.org/browse/WFLY-4020"},{"type":"WEB","url":"http://seclists.org/oss-sec/2014/q4/830"},{"type":"WEB","url":"http://www.securityfocus.com/bid/71328"}],"affected":[{"package":{"name":"io.undertow:undertow-core","ecosystem":"Maven","purl":"pkg:maven/io.undertow/undertow-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.0.0"},{"fixed":"1.0.17"}]}],"versions":["1.0.0.Final","1.0.1.Final","1.0.10.Final","1.0.11.Final","1.0.12.Final","1.0.13.Final","1.0.14.Final","1.0.15.Final","1.0.16.Final","1.0.2.Final","1.0.3.Final","1.0.4.Final","1.0.5.Final","1.0.6.Final","1.0.7.Final","1.0.8.Final","1.0.9.Final"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h6p6-fc4w-cqhx/GHSA-h6p6-fc4w-cqhx.json"}},{"package":{"name":"io.undertow:undertow-core","ecosystem":"Maven","purl":"pkg:maven/io.undertow/undertow-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.1.0.Beta1"},{"fixed":"1.1.0.CR5"}]}],"versions":["1.1.0.Beta1","1.1.0.Beta2","1.1.0.Beta3","1.1.0.Beta4","1.1.0.Beta5","1.1.0.Beta6","1.1.0.Beta7","1.1.0.Beta8","1.1.0.CR1","1.1.0.CR2","1.1.0.CR3","1.1.0.CR4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h6p6-fc4w-cqhx/GHSA-h6p6-fc4w-cqhx.json","last_known_affected_version_range":"\u003c= 1.1.0.CR4"}},{"package":{"name":"io.undertow:undertow-core","ecosystem":"Maven","purl":"pkg:maven/io.undertow/undertow-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.2.0.Beta1"},{"fixed":"1.2.0.Beta3"}]}],"versions":["1.2.0.Beta1","1.2.0.Beta2"],"database_specific":{"last_known_affected_version_range":"\u003c= 1.2.0.Beta2","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h6p6-fc4w-cqhx/GHSA-h6p6-fc4w-cqhx.json"}}],"schema_version":"1.9.0"}