Back

CRITICAL

undertow: AJP File Read/Inclusion Vulnerability

Published Apr 28, 2020

Description

A file inclusion vulnerability was found in the AJP connector enabled with a default AJP configuration port of 8009 in Undertow version 2.0.29.Final and before and was fixed in 2.0.30.Final. A remote, unauthenticated attacker could exploit this vulnerability to read web application files from a vulnerable server. In instances where the vulnerable server allows file uploads, an attacker could upload malicious JavaServer Pages (JSP) code within a variety of file types and trigger this vulnerability to gain remote code execution.

Affected products

Remediation

Red Hat statement

Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251 and CVE page https://access.redhat.com/security/cve/cve-2020-1938

Red Hat mitigation

Please refer to the Red Hat knowledgebase article: https://access.redhat.com/solutions/4851251

Weaknesses (1)

References (11)

Change history (4)
  1. MITRE
    • CVSS vector

      changed from CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L to CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

    • CVSS score

      changed from 7.6 to 8.6

  2. Red Hat
    • CVSS vector

      changed from CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L to CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

    • CVSS score

      changed from 8.6 to 7.6

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 28, 2020
Updated Aug 4, 2024
Reserved Nov 27, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Feb 26, 2020
ENISA EUVD
Assigner redhat
Published Apr 28, 2020
Updated Aug 4, 2024
Exploited since n/a
EUVD-2022-4009 GHSA-GV2W-88HX-8M9R