Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9442-gm4v-r222

Опубликовано: 20 июн. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Undertow's url-encoded request path information can be broken on ajp-listener

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.3.0.Alpha1, < 2.3.14.Final

2.3.14.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.33.Final

2.2.33.Final

EPSS

Процентиль: 83%
0.02024
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.

CVSS3: 7.5
redhat
больше 1 года назад

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.

CVSS3: 7.5
nvd
больше 1 года назад

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.

CVSS3: 7.5
debian
больше 1 года назад

A vulnerability was found in Undertow, where URL-encoded request paths ...

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость класса AjpRequestParser компонента ajp-listener веб-сервера Undertow, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 83%
0.02024
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400