Undertow Missing Authorization when requesting a protected directory without trailing slash
High severity
GitHub Reviewed
Published
Aug 1, 2019
to the GitHub Advisory Database
•
Updated Sep 25, 2023
Description
Published by the National Vulnerability Database
Jul 25, 2019
Reviewed
Aug 1, 2019
Published to the GitHub Advisory Database
Aug 1, 2019
Last updated
Sep 25, 2023
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
References