A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.4.37"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-NA"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.4.37-sp9"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3688.json"