REDHAT-BUG-1534343: Path Traversal
It was found that the AJP connector in undertow does not use the ALLOWENCODEDSLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1534343?
The severity of REDHAT-BUG-1534343 is considered high due to the potential for path traversal and information disclosure.
How do I fix REDHAT-BUG-1534343?
To fix REDHAT-BUG-1534343, you need to update the Undertow connector configuration to use the ALLOW_ENCODED_SLASH option.
What is the impact of REDHAT-BUG-1534343?
The impact of REDHAT-BUG-1534343 can lead to unauthorized access to arbitrary local files on the server.
Which software is affected by REDHAT-BUG-1534343?
The software affected by REDHAT-BUG-1534343 is the Undertow application server.
Can REDHAT-BUG-1534343 lead to remote code execution?
No, REDHAT-BUG-1534343 does not directly lead to remote code execution but allows for potential information disclosure.