CVE-2020-1757

HIGHCVSS 8.1/10EPSS 1.57%

Last modified

CVE-2020-1757 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.. EPSS estimates a 1.57% chance of exploitation in the next 30 days.

Description

A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.

Metrics

CVSS 3.1
8.1/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

EPSS Probability
1.57%

72.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
RedhatUndertow< 2.1.0
RedhatUndertow2.0.0Sp1
RedhatUndertow2.0.25Sp1
RedhatUndertow2.0.26Sp3
RedhatUndertow2.0.28Sp1
RedhatJboss Data Grid7.0.0
RedhatJboss Enterprise Application Platform7.0.0
RedhatJboss Fuse6.0.0
RedhatJboss Fuse7.0.0
RedhatOpenshift Application RuntimesAll versions
RedhatSingle Sign-On7.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-1757?
A flaw was found in all undertow-2.x.x SP1 versions prior to undertow-2.0.30.SP1, all undertow-1.x.x and undertow-2.x.x versions prior to undertow-2.1.0.Final, where the Servlet container causes servletPath to normalize incorrectly by truncating the path after semicolon which may lead to an application mapping resulting in the security bypass.
How severe is CVE-2020-1757?
CVE-2020-1757 has a CVSS score of 8.1/10 (HIGH severity). The EPSS model estimates a 1.57% probability of exploitation in the next 30 days.
How do I fix CVE-2020-1757?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-1757?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST