Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-97cq-f4jm-mv8h

Опубликовано: 07 нояб. 2024
Источник: github
Github: Прошло ревью
CVSS4: 6.6
CVSS3: 7.5

Описание

Undertow Denial of Service vulnerability

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.2.32.Final

2.2.32.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.3.0.Alpha1, < 2.3.13.Final

2.3.13.Final

EPSS

Процентиль: 72%
0.00727
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
redhat
почти 2 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMech ...

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость пакета Undertow программного обеспечения Red Hat JBoss Enterprise Application Platform, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00727
Низкий

6.6 Medium

CVSS4

7.5 High

CVSS3

Дефекты

CWE-20
CWE-400