High severity7.5NVD Advisory· Published Jul 25, 2019· Updated Jun 17, 2026
CVE-2019-10184
CVE-2019-10184
Description
undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
io.undertow:undertow-servletMaven | < 2.0.23 | 2.0.23 |
Affected products
17cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*+ 4 more
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*+ 1 more
- cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:openshift_application_runtimes:1.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*+ 2 more
- cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:single_sign-on:7.3:*:*:*:*:*:*:*
- Range: fixed in 2.0.23.Final
Patches
Vulnerability mechanics
References
18- github.com/undertow-io/undertow/pull/794nvdPatchThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2935nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2936nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2937nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2938nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:2998nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3044nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3045nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3046nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2019:3050nvdVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0727nvdVendor AdvisoryWEB
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-w69w-jvc7-wjgvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-10184ghsaADVISORY
- security.netapp.com/advisory/ntap-20220210-0016/nvdThird Party Advisory
- github.com/undertow-io/undertow/commit/5fa7ac68c0e4251c93056d9982db5e794e04ebfaghsaWEB
- issues.redhat.com/browse/UNDERTOW-1578ghsaWEB
- security.netapp.com/advisory/ntap-20220210-0016ghsaWEB
News mentions
0No linked articles in our index yet.