CVE-2014-7816 is a directory traversal vulnerability affecting JBoss Undertow versions 1.0.x, 1.1.x, and 1.2.x when deployed on Windows systems. This flaw allows unauthenticated remote attackers to read arbitrary files by manipulating resource URIs with ".." sequences. With a CVSS score of 5.0 and an EPSS percentile higher than 98% of all CVEs, it presents a moderate risk, primarily impacting confidentiality. While not on the KEV catalog, a Metasploit module exists for exploitation, though there is no evidence of widespread active exploitation or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.0.16CPE matchmatch criteria | cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:* | ||
<= 1.1.0CPE matchmatch criteria | cpe:2.3:a:redhat:undertow:*:cr4:*:*:*:*:*:* | ||
<= 1.2.0CPE matchmatch criteria | cpe:2.3:a:redhat:undertow:*:beta2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.