CVE-2014-7816: Red Hat Undertow
Medium severity, CVSS 5.0. EPSS: 25.1% chance of exploitation in the next 30 days.
Directory traversal vulnerability in JBoss Undertow 1.0.x before 1.0.17, 1.1.x before 1.1.0.CR5, and 1.2.x before 1.2.0.Beta3, when running on Windows, allows remote attackers to read arbitrary files via a .. (dot dot) in a resource URI.
Affected products
- Red Hat Undertow: up to and including 1.0.16; up to and including 1.1.0; up to and including 1.2.0
Published 2014-12-01. Last modified 2026-06-17.