CVE-2018-14642
Last modified
CVE-2018-14642 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.. EPSS estimates a 2.11% chance of exploitation in the next 30 days.
Description
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Redhat | Undertow | All versions |
| Redhat | Jboss Enterprise Application Platform | 7.1 |
| Redhat | Jboss Enterprise Application Platform | 7.2 |
| Redhat | Jboss Enterprise Application Platform | 7.3 |
References
- https://access.redhat.com/errata/RHSA-2019:0362Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0364Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0365Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0380Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1106Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1107Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1108Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1140Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14642Issue Tracking, Patch, Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0362Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0364Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0365Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:0380Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1106Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1107Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1108Vendor Advisory
- https://access.redhat.com/errata/RHSA-2019:1140Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14642Issue Tracking, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14642?
How severe is CVE-2018-14642?
How do I fix CVE-2018-14642?
Are you affected by CVE-2018-14642?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
