Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2020-10705

Опубликовано: 10 июн. 2020
Источник: debian

Описание

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowfixed2.1.1-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1803241

  • https://github.com/undertow-io/undertow/commit/b53d4589c586e8bbdcc89ed60f32cd7977e9a4f4

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 5 лет назад

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.

CVSS3: 7.5
redhat
больше 5 лет назад

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.

CVSS3: 7.5
nvd
больше 5 лет назад

A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.

CVSS3: 7.5
github
почти 5 лет назад

Allocation of Resources Without Limits or Throttling in Undertow