CVE-2010-1429
Last modified
CVE-2010-1429 is a vulnerability of currently unknown severity. Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.. EPSS estimates a 53.73% chance of exploitation in the next 30 days.
Description
Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP09 and 4.3 before 4.3.0.CP08 allows remote attackers to obtain sensitive information about "deployed web contexts" via a request to the status servlet, as demonstrated by a full=true query string. NOTE: this issue exists because of a CVE-2008-3273 regression.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Redhat | Jboss Enterprise Application Platform | <= 4.2.0 | Cp08 |
| Redhat | Jboss Enterprise Application Platform | <= 4.3.0 | Cp07 |
| Redhat | Jboss Enterprise Application Platform | 4.2 | — |
| Redhat | Jboss Enterprise Application Platform | 4.2.0 | Cp01 |
| Redhat | Jboss Enterprise Application Platform | 4.3 | — |
| Redhat | Jboss Enterprise Application Platform | 4.3.0 | Cp01 |
References
- http://secunia.com/advisories/39563Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0992Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
- http://secunia.com/advisories/39563Vendor Advisory
- http://www.vupen.com/english/advisories/2010/0992Vendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0376.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0377.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0378.htmlVendor Advisory
- https://rhn.redhat.com/errata/RHSA-2010-0379.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-1429?
How severe is CVE-2010-1429?
How do I fix CVE-2010-1429?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-1423Argument injection vulnerability in the URI handler in (a) J…
- CVE-2010-1424Unspecified vulnerability in JustSystems Ichitaro and Ichita…
- CVE-2010-1425F-Secure Internet Security 2010 and earlier; Anti-Virus for …
- CVE-2010-1426SQL injection vulnerability in MODx Evolution before 1.0.3 a…
- CVE-2010-1427Cross-site scripting (XSS) vulnerability in the SearchHighli…
- CVE-2010-1428The Web Console (aka web-console) in JBossAs in Red Hat JBos…7.5
- CVE-2010-1430Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2010-1431SQL injection vulnerability in templates_export.php in Cacti…
- CVE-2010-1432Joomla! Core is prone to an information disclosure vulnerabi…7.5
- CVE-2010-1433Joomla! Core is prone to a vulnerability that lets attackers…9.8
- CVE-2010-1434Joomla! Core is prone to a session fixation vulnerability. A…7.5
- CVE-2010-1435Joomla! Core is prone to a security bypass vulnerability. Ex…9.8
Are you affected by CVE-2010-1429?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
