Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-1973

Опубликовано: 07 нояб. 2024
Источник: debian
EPSS Низкий

Описание

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
undertowfixed2.3.18-1package

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=2185662

  • https://github.com/undertow-io/undertow/commit/0410f3c4d9b39b754a2203a29834cac51da11258

EPSS

Процентиль: 72%
0.00727
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
redhat
почти 2 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
github
больше 1 года назад

Undertow Denial of Service vulnerability

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость пакета Undertow программного обеспечения Red Hat JBoss Enterprise Application Platform, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00727
Низкий