← back
CVE-2018-14642mediumCWE-200

CVE-2018-14642

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 2.1%
exploitation probability
2.1%top 19% of all CVEs
observed exploitation
nono source reports it
An information leak vulnerability was found in Undertow. If all headers are not written out in the first write() call then the code that handles flushing the buffer will always write out the full contents of the writevBuffer buffer, which may contain data from previous requests.
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
Red Hat · undertow