CVE-2024-1459: Red Hat Undertow

Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.

A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories.

Affected products

  • Red Hat Undertow: affected versions not specified

Published 2024-02-12. Last modified 2026-08-04.