2.3.20.Final
12 years ago
9 days ago
Known vulnerabilities in the io.undertow:undertow-servlet package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
io.undertow:undertow-servlet is a Servlet 4.0 implementation for Undertow Affected versions of this package are vulnerable to NULL Pointer Dereference. NullPointerException occurred if a servlet calls How to fix NULL Pointer Dereference? Upgrade | [0,2.0.34.Final)[2.1.0.Final,2.1.6.Final)[2.2.0.Final,2.2.4.Final) |
io.undertow:undertow-servlet is a Servlet 4.0 implementation for Undertow Affected versions of this package are vulnerable to Denial of Service (DoS). Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters. How to fix Denial of Service (DoS)? Upgrade | [,2.0.33.Final)[2.1.0.Final,2.1.5.Final)[2.2.0.Final,2.2.3.Final) |
io.undertow:undertow-servlet is a Servlet 4.0 implementation for Undertow Affected versions of this package are vulnerable to Security Bypass. The How to fix Security Bypass? Upgrade | [,2.1.0.Final) |