CVE-2018-14642
CVE-2018-14642
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.3EPSS 2.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
18 set 2018Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Produtos afetados
Red Hat · undertowQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://access.redhat.com/errata/RHSA-2019:0362https://access.redhat.com/errata/RHSA-2019:0364https://access.redhat.com/errata/RHSA-2019:0365https://access.redhat.com/errata/RHSA-2019:0380https://access.redhat.com/errata/RHSA-2019:1106https://access.redhat.com/errata/RHSA-2019:1107https://access.redhat.com/errata/RHSA-2019:1108https://access.redhat.com/errata/RHSA-2019:1140https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14642