{"affected": [{"affectedData": [{"collectionURL": "https://github.com/undertow-io/undertow", "defaultStatus": "unaffected", "packageName": "undertow", "versions": [{"lessThan": "2.3.12", "status": "affected", "version": "0", "versionType": "custom"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-activemq-artemis", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.16.0-18.redhat_00052.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-apache-cxf", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.4.10-2.redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-eclipse-jgit", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.13.3.202401111512-1.r_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-elytron-web", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.9.4-1.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-hal-console", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.3.21-1.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-hibernate", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.3.36-1.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-infinispan", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:11.0.18-2.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-insights-java-client", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.1.2-1.redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jberet", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.3.9-3.SP3_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jboss-annotations-api_1.3_spec", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.0.1-3.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jboss-cert-helper", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.1.2-1.redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jboss-remoting", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.0.27-4.SP2_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jboss-server-migration", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.10.0-35.Final_redhat_00034.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jboss-xnio-base", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.8.12-1.SP2_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-jgroups-kubernetes", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.0.17-1.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-lucene-solr", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.5.5-6.redhat_2.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-undertow", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.2.30-1.SP1_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-wildfly", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:7.4.16-4.GA_redhat_00002.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8"], "defaultStatus": "affected", "packageName": "eap7-wildfly-elytron", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.15.22-1.Final_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-activemq-artemis", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.16.0-18.redhat_00052.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-apache-cxf", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.4.10-2.redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-eclipse-jgit", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.13.3.202401111512-1.r_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-elytron-web", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.9.4-1.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-hal-console", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.3.21-1.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-hibernate", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.3.36-1.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-infinispan", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:11.0.18-2.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-insights-java-client", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.1.2-1.redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jberet", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.3.9-3.SP3_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jboss-annotations-api_1.3_spec", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.0.1-3.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jboss-cert-helper", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.1.2-1.redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jboss-remoting", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.0.27-4.SP2_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jboss-server-migration", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.10.0-35.Final_redhat_00034.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jboss-xnio-base", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.8.12-1.SP2_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-jgroups-kubernetes", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.0.17-1.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-lucene-solr", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.5.5-6.redhat_2.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-undertow", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.2.30-1.SP1_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-wildfly", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:7.4.16-4.GA_redhat_00002.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9"], "defaultStatus": "affected", "packageName": "eap7-wildfly-elytron", "product": "Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.15.22-1.Final_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-activemq-artemis", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.16.0-18.redhat_00052.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-apache-cxf", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.4.10-2.redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-eclipse-jgit", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.13.3.202401111512-1.r_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-elytron-web", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.9.4-1.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-hal-console", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.3.21-1.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-hibernate", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.3.36-1.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-infinispan", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:11.0.18-2.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-insights-java-client", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.1.2-1.redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jberet", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.3.9-3.SP3_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jboss-annotations-api_1.3_spec", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.0.1-3.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jboss-cert-helper", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.1.2-1.redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jboss-remoting", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.0.27-4.SP2_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jboss-server-migration", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.10.0-35.Final_redhat_00034.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jboss-xnio-base", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:3.8.12-1.SP2_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-jgroups-kubernetes", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.0.17-1.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-lucene-solr", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:5.5.5-6.redhat_2.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-undertow", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.2.30-1.SP1_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-wildfly", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:7.4.16-4.GA_redhat_00002.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7"], "defaultStatus": "affected", "packageName": "eap7-wildfly-elytron", "product": "Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:1.15.22-1.Final_redhat_00001.1.el7eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:8.0"], "defaultStatus": "unaffected", "product": "Red Hat JBoss Enterprise Application Platform 8", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9", "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"], "defaultStatus": "affected", "packageName": "eap8-undertow", "product": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.3.11-1.SP1_redhat_00001.1.el8eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el9", "cpe:/a:redhat:jboss_enterprise_application_platform:8.0::el8"], "defaultStatus": "affected", "packageName": "eap8-undertow", "product": "Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 9", "vendor": "Red Hat", "versions": [{"lessThan": "*", "status": "unaffected", "version": "0:2.3.11-1.SP1_redhat_00001.1.el9eap", "versionType": "rpm"}]}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:quarkus:2"], "defaultStatus": "unaffected", "packageName": "io.quarkus/quarkus-undertow", "product": "Red Hat build of Quarkus", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_data_grid:8"], "defaultStatus": "affected", "packageName": "undertow", "product": "Red Hat Data Grid 8", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_brms_platform:7"], "defaultStatus": "unknown", "packageName": "undertow", "product": "Red Hat Decision Manager 7", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_fuse:7"], "defaultStatus": "unknown", "packageName": "undertow", "product": "Red Hat Fuse 7", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html", "cpes": ["cpe:/a:redhat:jboss_data_grid:7"], "defaultStatus": "unknown", "packageName": "undertow", "product": "Red Hat JBoss Data Grid 7", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/jbossnetwork/restricted/listSoftware.html", "cpes": ["cpe:/a:redhat:jboss_fuse:6"], "defaultStatus": "unknown", "packageName": "undertow", "product": "Red Hat JBoss Fuse 6", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:jboss_enterprise_bpms_platform:7"], "defaultStatus": "unknown", "packageName": "undertow", "product": "Red Hat Process Automation 7", "vendor": "Red Hat"}, {"collectionURL": "https://access.redhat.com/downloads/content/package-browser/", "cpes": ["cpe:/a:redhat:red_hat_single_sign_on:7"], "defaultStatus": "unknown", "packageName": "undertow", "product": "Red Hat Single Sign-On 7", "vendor": "Red Hat"}], "source": "
[email protected]"}], "configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:a:redhat:undertow:-:*:*:*:*:*:*:*", "matchCriteriaId": "8190B427-8350-43AE-8F54-6A40B701C95E", "vulnerable": true}], "negate": false, "operator": "OR"}]}], "cveTags": [], "descriptions": [{"lang": "en", "value": "A path traversal vulnerability was found in Undertow. This issue may allow a remote attacker to append a specially-crafted sequence to an HTTP request for an application deployed to JBoss EAP, which may permit access to privileged or restricted files and directories."}, {"lang": "es", "value": "Se encontr\u00f3 una vulnerabilidad de path traversal en Undertow. Este problema puede permitir que un atacante remoto agregue una secuencia especialmente manipulada a una solicitud HTTP para una aplicaci\u00f3n implementada en JBoss EAP, lo que puede permitir el acceso a archivos y directorios privilegiados o restringidos."}], "id": "CVE-2024-1459", "lastModified": "2026-06-17T07:04:17.263", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "
[email protected]", "type": "Secondary"}, {"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 1.4, "source": "
[email protected]", "type": "Primary"}], "ssvcV203": [{"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "ssvcData": {"id": "CVE-2024-1459", "options": [{"exploitation": "none"}, {"automatable": "no"}, {"technicalImpact": "partial"}], "role": "CISA Coordinator", "timestamp": "2024-02-13T15:51:43.437025Z", "version": "2.0.3"}}]}, "published": "2024-02-12T21:15:08.533", "references": [{"source": "
[email protected]", "url": "https://access.redhat.com/errata/RHSA-2024:1674"}, {"source": "
[email protected]", "url": "https://access.redhat.com/errata/RHSA-2024:1675"}, {"source": "
[email protected]", "url": "https://access.redhat.com/errata/RHSA-2024:1676"}, {"source": "
[email protected]", "url": "https://access.redhat.com/errata/RHSA-2024:2763"}, {"source": "
[email protected]", "url": "https://access.redhat.com/errata/RHSA-2024:2764"}, {"source": "
[email protected]", "tags": ["Vendor Advisory"], "url": "https://access.redhat.com/security/cve/CVE-2024-1459"}, {"source": "
[email protected]", "tags": ["Issue Tracking"], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259475"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://access.redhat.com/errata/RHSA-2024:1677"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://access.redhat.com/errata/RHSA-2024:2763"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://access.redhat.com/errata/RHSA-2024:2764"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Vendor Advisory"], "url": "https://access.redhat.com/security/cve/CVE-2024-1459"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Issue Tracking"], "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2259475"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "url": "https://security.netapp.com/advisory/ntap-20241122-0008/"}], "sourceIdentifier": "
[email protected]", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-24"}], "source": "
[email protected]", "type": "Secondary"}]}