{"id":"CVE-2018-1047","details":"A flaw was found in Wildfly 9.x. A path traversal vulnerability through the org.wildfly.extension.undertow.deployment.ServletResourceManager.getResource method could lead to information disclosure of arbitrary local files.","aliases":["GHSA-fmr4-w67p-vh8x"],"modified":"2026-07-07T08:49:38.856117856Z","published":"2018-01-24T23:29:00.527Z","database_specific":{"unresolved_ranges":[{"vendor_product":"redhat:jboss_enterprise_application_platform","cpes":["cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.1.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"7.1.0"},{"last_affected":"7.1.0"}],"source":"CPE_STRING"},{"extracted_events":[{"introduced":"9.0.0-alpha1"},{"last_affected":"9.0.0-alpha1"}],"source":"CPE_STRING","vendor_product":"redhat:jboss_wildfly_application_server","cpes":["cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.0:alpha1:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1247"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1248"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1249"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:1251"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2018:2938"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1528361"},{"type":"REPORT","url":"https://issues.jboss.org/browse/WFLY-9620"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/wildfly/wildfly","events":[{"introduced":"bb382e0b0c80920ae33d9ef4bb568a28cc7e8477"},{"last_affected":"95fa2360ea2f698378c730d40eb3ee3812f271a9"}],"database_specific":{"extracted_events":[{"introduced":"9.0.0"},{"last_affected":"9.0.0"},{"introduced":"9.0.0-beta1"},{"last_affected":"9.0.0-beta1"},{"introduced":"9.0.0-beta2"},{"last_affected":"9.0.0-beta2"},{"introduced":"9.0.0-cr1"},{"last_affected":"9.0.0-cr1"},{"introduced":"9.0.0-cr2"},{"last_affected":"9.0.0-cr2"},{"introduced":"9.0.1"},{"last_affected":"9.0.1"},{"introduced":"9.0.2"},{"last_affected":"9.0.2"},{"introduced":"10.0.0"},{"last_affected":"10.0.0"},{"introduced":"10.0.0-alpha1"},{"last_affected":"10.0.0-alpha1"},{"introduced":"10.0.0-alpha2"},{"last_affected":"10.0.0-alpha2"},{"introduced":"10.0.0-alpha3"},{"last_affected":"10.0.0-alpha3"},{"introduced":"10.0.0-alpha4"},{"last_affected":"10.0.0-alpha4"},{"introduced":"10.0.0-alpha5"},{"last_affected":"10.0.0-alpha5"},{"introduced":"10.0.0-alpha6"},{"last_affected":"10.0.0-alpha6"},{"introduced":"10.0.0-beta1"},{"last_affected":"10.0.0-beta1"},{"introduced":"10.0.0-beta2"},{"last_affected":"10.0.0-beta2"},{"introduced":"10.0.0-cr1"},{"last_affected":"10.0.0-cr1"},{"introduced":"10.0.0-cr2"},{"last_affected":"10.0.0-cr2"},{"introduced":"10.0.0-cr3"},{"last_affected":"10.0.0-cr3"},{"introduced":"10.0.0-cr4"},{"last_affected":"10.0.0-cr4"},{"introduced":"10.0.0-cr5"},{"last_affected":"10.0.0-cr5"},{"introduced":"10.1.0"},{"last_affected":"10.1.0"},{"introduced":"10.1.0-cr1"},{"last_affected":"10.1.0-cr1"},{"introduced":"11.0.0"},{"last_affected":"11.0.0"},{"introduced":"11.0.0-alpha1"},{"last_affected":"11.0.0-alpha1"},{"introduced":"11.0.0-beta1"},{"last_affected":"11.0.0-beta1"},{"introduced":"11.0.0-cr1"},{"last_affected":"11.0.0-cr1"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.0:beta2:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.0:cr1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.0:cr2:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.1:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:9.0.2:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:alpha2:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:alpha3:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:alpha4:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:alpha5:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:alpha6:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:beta2:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:cr1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:cr2:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:cr3:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:cr4:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.0.0:cr5:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.1.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:10.1.0:cr1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:11.0.0:*:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:11.0.0:alpha1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:11.0.0:beta1:*:*:*:*:*:*","cpe:2.3:a:redhat:jboss_wildfly_application_server:11.0.0:cr1:*:*:*:*:*:*"]}}],"versions":["10.0.0","10.0.0-alpha1","10.0.0-alpha2","10.0.0-alpha3","10.0.0-alpha4","10.0.0-alpha5","10.0.0-alpha6","10.0.0-beta1","10.0.0-beta2","10.0.0-cr1","10.0.0-cr2","10.0.0-cr3","10.0.0-cr4","10.0.0-cr5","10.1.0","10.1.0-cr1","11.0.0","11.0.0-alpha1","11.0.0-beta1","11.0.0-cr1","9.0.0","9.0.0-beta1","9.0.0-beta2","9.0.0-cr1","9.0.0-cr2","9.0.1","9.0.2"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1047.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}