Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gjjx-gqm4-wcgm

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Uncontrolled Resource Consumption in Undertow

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

<= 1.4.24.FInal

1.4.25.Final

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.0.0.Alpha1, <= 2.0.4.Final

2.0.5.Final

EPSS

Процентиль: 72%
0.00707
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

CVSS3: 6.5
redhat
почти 8 лет назад

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

CVSS3: 6.5
nvd
больше 7 лет назад

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

CVSS3: 6.5
debian
больше 7 лет назад

It was found that URLResource.getLastModified() in Undertow closes the ...

EPSS

Процентиль: 72%
0.00707
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-400