CVE-2018-14642
MEDIUM severity · CVSS 5.3 · Information disclosure
5.3CVSS MEDIUM
Summary
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactLow
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)2%
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- https://access.redhat.com/errata/RHSA-2019:0362Advisory
- https://access.redhat.com/errata/RHSA-2019:0364Advisory
- https://access.redhat.com/errata/RHSA-2019:0365Advisory
- https://access.redhat.com/errata/RHSA-2019:0380Advisory
- https://access.redhat.com/errata/RHSA-2019:1106Advisory
- https://access.redhat.com/errata/RHSA-2019:1107Advisory
- https://access.redhat.com/errata/RHSA-2019:1108Advisory
- https://access.redhat.com/errata/RHSA-2019:1140Advisory