Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bugs Could Occur When Importing Jar undertow-servlet-1.4.20.Final.jar in This Project #52

Open
WHATSUPTOYOU opened this issue Nov 9, 2020 · 0 comments

Comments

@WHATSUPTOYOU
Copy link

Hi Developer, I found that your project uses a vulnerable jar which is undertow-servlet-1.4.20.Final.jar and calls the vulnerable function handleRequest in file ServletInitialHandler.java (See details in Repository undertow-io/undertow, commitid: d2715e3afa13f50deaa19643676816ce391551e9)
The CVE number of this vulnerability is CVE-2019-10184
If this project is still in use, please check it and fix this bug as soon as possible. You can update the imported jar undertow-servlet-1.4.20.Final.jar to version over 2.0.23.Final to avoid this bug, thx.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant