Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5r46-q4x7-6fx6

Опубликовано: 01 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

EPSS

Процентиль: 77%
0.01024
Низкий

7.5 High

CVSS3

Дефекты

CWE-252

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

CVSS3: 7.5
redhat
почти 4 года назад

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improperly sending two response packets, and those packets have the reuse flag set even though JBoss EAP closes the connection. A failure occurs when the connection is reused after a 400 by CPING since it reads in the second SEND_HEADERS response packet instead of a CPONG.

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Undertow. For an AJP 400 response, EAP 7 is improp ...

EPSS

Процентиль: 77%
0.01024
Низкий

7.5 High

CVSS3

Дефекты

CWE-252