CVE-2021-3688

Description

A flaw was found in Red Hat JBoss Core Services HTTP Server in all versions, where it does not properly normalize the path component of a request URL contains dot-dot-semicolon(s). This flaw could allow an attacker to access unauthorized information or possibly conduct further attacks. The highest threat from this vulnerability is to data confidentiality and integrity.

Mitigation

Manually add LocationMatch directive to deny any possible problem requests in the JBCS httpd configuration. For example:

<LocationMatch ".*\.\.;.*">
Require all denied
</LocationMatch>

Common Vulnerability Scoring System (CVSS) Score Details

Info alert:Important note

CVSS scores for open source components depend on vendor-specific factors (e.g. version or build chain). Therefore, Red Hat's score and impact rating can be different from NVD and other vendors. Red Hat remains the authoritative CVE Naming Authority (CNA) source for its products and services (see Red Hat classifications).

CVSS v3 Score Breakdown

Red HatNVDcve.org
Base Score4.84.8N/A
Attack VectorNetworkNetworkN/A
Attack ComplexityHighHighN/A
Privileges RequiredNoneNoneN/A
User InteractionNoneNoneN/A
ScopeUnchangedUnchangedN/A
ConfidentialityLowLowN/A
Integrity ImpactLowLowN/A
Availability ImpactNoneNoneN/A

Vector

Red Hat: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

NVD: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Red Hat CVSS v3 Score Explanation

AC:H, because mod_proxy and mod_cluster are NOT the default configuration and the vulnerability can be exploited only if the attacker knows what path is deployed on the app server. These conditions can be the "under certain circumstances" which are beyond attacker's control.

C:L and I:L, because the bug is related to a user who is running the servers. The leak/modification is limited to a user's authority in the OS. An attacker can't get everything of the system and cannot have control over the information.

Understanding the Weakness (CWE)

Confidentiality

Technical Impact: Read Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.