{"id":"CVE-2018-1047","aliases":["GHSA-fmr4-w67p-vh8x"],"url":"https://o3.security/vulnerability/CVE-2018-1047","summary":"Improper Input Validation in org.wildfly:wildfly-undertow","details":"A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.","published":"2018-01-24T23:29:00.527Z","modified":"2026-07-08T05:50:43.876387657Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.wildfly:wildfly-undertow","fixedVersion":"12.0.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1247"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1248"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1249"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1251"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2938"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1528361"},{"type":"REPORT","url":"https://issues.jboss.org/browse/WFLY-9620"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1047"},{"type":"WEB","url":"https://access.redhat.com/security/cve/CVE-2018-1047"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-fmr4-w67p-vh8x"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:50:43.876387657Z"}}