Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1108

Опубликовано: 14 сент. 2023
Источник: debian
EPSS Низкий

Описание

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowfixed2.3.8-1experimentalpackage
undertowfixed2.3.8-2package

Примечания

  • https://issues.redhat.com/browse/UNDERTOW-2239

  • https://github.com/undertow-io/undertow/pull/1453

EPSS

Процентиль: 77%
0.01771
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 3 лет назад

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

CVSS3: 7.5
redhat
больше 3 лет назад

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

CVSS3: 7.5
nvd
около 3 лет назад

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

CVSS3: 7.5
github
около 3 лет назад

Undertow denial of service vulnerability

CVSS3: 7.5
fstec
больше 3 лет назад

Уязвимость веб-сервера Undertow, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 77%
0.01771
Низкий