Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fj7c-vg2v-ccrm

Опубликовано: 15 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Undertow vulnerable to memory exhaustion due to buffer leak

Buffer leak on incoming WebSocket PONG message(s) in Undertow before 2.0.40 and 2.2.10 can lead to memory exhaustion and allow a denial of service.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.0.40

2.0.40

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.2.0, < 2.2.10

2.2.10

EPSS

Процентиль: 51%
0.00278
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-401

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 3 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

CVSS3: 7.5
redhat
больше 4 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

CVSS3: 7.5
nvd
больше 3 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.

CVSS3: 7.5
debian
больше 3 лет назад

A flaw was found in Undertow. A buffer leak on the incoming WebSocket ...

EPSS

Процентиль: 51%
0.00278
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-401