A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "9.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-cr1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.0-cr2"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.1"
},
{
"introduced": "0"
},
{
"last_affected": "9.0.2"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-alpha1"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-alpha2"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-alpha3"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-alpha4"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-alpha5"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-alpha6"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-beta2"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-cr1"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-cr2"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-cr3"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-cr4"
},
{
"introduced": "0"
},
{
"last_affected": "10.0.0-cr5"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0"
},
{
"introduced": "0"
},
{
"last_affected": "10.1.0-cr1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-alpha1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-beta1"
},
{
"introduced": "0"
},
{
"last_affected": "11.0.0-cr1"
},
{
"introduced": "0"
},
{
"last_affected": "7.1.0"
}
]
}