Description
It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus allow the the slash / anti-slash characters encoded in the url which may lead to path traversal and result in the information disclosure of arbitrary local files.
Remediation
References
Related Vulnerabilities
MongoDb Other Vulnerability (CVE-2024-8305)
MediaWiki Improper Input Validation Vulnerability (CVE-2011-1580)
Drupal Core 7.x Cross-Site Scripting (7.0 - 7.72)
WordPress Plugin One page checkout and layouts for woocommerce Unspecified Vulnerability (2.7)
WordPress Plugin Custom Dashboard & Login Page-AGCA Cross-Site Request Forgery (6.5.4)