#VU27296 Input validation error in Undertow - CVE-2020-1757
Published: April 23, 2020
Undertow
Red Hat Inc.
Description
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to insufficient validation of user-supplied input in Servlet container that causes the servletPath to incorrectly normalize data by truncating the path after semicolon. A remote attacker can pass specially crafted input to the application and bypass security restrictions