Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

undertow — Vulnerabilities & Security Advisories 29

All 29 CVE vulnerabilities found in undertow, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) vulnerability data specifically associated with the Undertow web server developed by Red Hat. The collection encompasses a wide variety of security flaws, including buffer overflows, cross-site scripting, and improper access control issues, covering incidents reported from 2016 through the present. By consolidating these records, the resource allows security professionals and developers to efficiently track vendor security advisories related to Undertow, gain a deeper understanding of specific weakness classes as they manifest in this particular ecosystem, and examine the complete historical record of vulnerabilities affecting the product. This structured approach facilitates faster risk assessment and informed decision-making during patch management cycles. The data reflects known issues that have been publicly disclosed and tracked by major security databases, providing a centralized view for monitoring the security posture of systems relying on Undertow for HTTP and WebSocket protocols. Users can utilize this information to identify patterns in defect types, evaluate the impact of historical exploits on current deployments, and ensure that mitigation strategies are up to date. The focus remains strictly on factual security information to support technical analysis and operational security improvements without unnecessary commentary. All entries are organized to aid in quick reference, enabling teams to pinpoint critical updates and correlate them with specific software versions. This serves as a vital resource for maintaining the integrity and reliability of applications built on this Java-based web server infrastructure.

Vendor: Red Hat

CVE ID Title CVSS Severity Published
CVE-2022-4492 Red Hat Undertow 安全漏洞 5.9 - 2023-02-23
CVE-2022-2764 Red Hat Undertow 安全漏洞 CWE-400 4.9 - 2022-09-01
CVE-2022-1319 Red Hat Undertow 安全漏洞 CWE-252 7.5 - 2022-08-31
CVE-2022-1259 Red Hat Undertow 资源管理错误漏洞 CWE-400 7.5 - 2022-08-31
CVE-2021-3859 Red Hat Undertow 资源管理错误漏洞 CWE-214 7.5 - 2022-08-26
CVE-2021-3690 Red Hat JBoss Enterprise Application Platform资源管理错误漏洞 CWE-400 7.5 - 2022-08-23
CVE-2022-2053 Red Hat Undertow 资源管理错误漏洞 CWE-400 7.5 - 2022-08-05
CVE-2021-3597 Red Hat Undertow 竞争条件问题漏洞 CWE-362 5.9 - 2022-05-24
CVE-2021-3629 Red Hat Undertow 资源管理错误漏洞 CWE-400 5.9 - 2022-05-24
CVE-2019-19343 Red Hat Undertow 资源管理错误漏洞 CWE-400 7.5 - 2021-03-23
CVE-2020-27782 Red Hat Undertow 资源管理错误漏洞 CWE-400 7.5 - 2021-02-23
CVE-2021-20220 Red Hat Undertow 环境问题漏洞 CWE-444 6.5 - 2021-02-23
CVE-2020-10687 Red Hat Undertow 环境问题漏洞 CWE-444 4.8 - 2020-09-23
CVE-2020-10705 Red Hat Undertow 缓冲区错误漏洞 7.5 - 2020-06-10
CVE-2020-10719 Red Hat Undertow 环境问题漏洞 CWE-444 6.5 Medium 2020-05-26
CVE-2020-1745 Red Hat Undertow 信息泄露漏洞 CWE-285 8.6 High 2020-04-28
CVE-2020-1757 Red Hat Undertow 输入验证错误漏洞 CWE-20 8.1 - 2020-04-21
CVE-2019-14888 Red Hat Undertow 资源管理错误漏洞 CWE-400 7.5 - 2020-01-23
CVE-2019-10212 Red Hat Undertow 日志信息泄露漏洞 CWE-532 9.8 - 2019-10-02
CVE-2019-10184 Red Hat Undertow 信息泄露漏洞 CWE-862 5.3 - 2019-07-25
CVE-2019-3888 Red Hat Undertow 日志信息泄露漏洞 CWE-532 9.8 - 2019-06-12
CVE-2018-14642 Red Hat Undertow 信息泄露漏洞 CWE-200 5.3 - 2018-09-18
CVE-2018-1114 Red Hat Undertow 安全漏洞 CWE-400 7.5 - 2018-09-11
CVE-2017-12165 Red Hat Undertow 安全漏洞 CWE-444 9.1 - 2018-07-27
CVE-2017-2670 Red Hat Undertow 资源管理错误漏洞 CWE-835 7.5 - 2018-07-27
CVE-2017-2666 Red Hat Undertow 环境问题漏洞 CWE-444 6.5 - 2018-07-27
CVE-2018-1067 Red Hat Undertow 安全漏洞 CWE-113 8.2 - 2018-05-21
CVE-2017-12196 Red Hat Undertow 安全漏洞 CWE-287 7.4 - 2018-04-18
CVE-2017-7559 Red Hat Undertow 安全漏洞 CWE-444 6.1 - 2018-01-10

All 29 known CVE vulnerabilities affecting undertow with full Chinese analysis, references, and POCs where available.