CVE-2018-14642

Description

An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.

Risk Information

Base Score
5.3
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
0.746

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2018-14642 are fixed in Undertow-core 2.0.19Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.1Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.2Windows
Multiple Vulnerabilities are affected in Red Hat JBoss Enterprise Application Platform 7 7.3Windows
Vulnerabilities CVE-2018-14642 are fixed in Undertow-core for Linux 2.0.19Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234