CVE Published: 26/08/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: redhat |
Vendor: n/a |
Product: Red Hat JBCS HTTP Server Status : PUBLISHED
CVE-2021-3688 Description
A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.