VYPR
High severity7.5NVD Advisory· Published Jul 25, 2019· Updated Jun 17, 2026

CVE-2019-10184

CVE-2019-10184

Description

undertow before version 2.0.23.Final is vulnerable to an information leak issue. Web apps may have their directory structures predicted through requests without trailing slashes via the api.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
io.undertow:undertow-servletMaven
< 2.0.232.0.23

Affected products

17
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*+ 2 more
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
    • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
  • cpe:2.3:a:redhat:jboss_data_grid:-:*:*:*:text-only:*:*:*
  • cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*+ 4 more
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:-:*:*:*:text-only:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.3:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.4:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*+ 1 more
    • cpe:2.3:a:redhat:openshift_application_runtimes:-:*:*:*:text-only:*:*:*
    • cpe:2.3:a:redhat:openshift_application_runtimes:1.0:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*+ 2 more
    • cpe:2.3:a:redhat:single_sign-on:-:*:*:*:text-only:*:*:*
    • cpe:2.3:a:redhat:single_sign-on:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:redhat:single_sign-on:7.3:*:*:*:*:*:*:*
  • cpe:2.3:a:redhat:undertow:*:*:*:*:*:*:*:*
    Range: <2.0.23
  • ghsa-coords
    Range: < 2.0.23
  • Range: fixed in 2.0.23.Final

Patches

Vulnerability mechanics

References

18

News mentions

0

No linked articles in our index yet.