Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rhcw-wjcm-9h6g

Опубликовано: 09 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of service in Undertow

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

Пакеты

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

>= 2.1.0, < 2.1.5

2.1.5

Наименование

io.undertow:undertow-core

maven
Затронутые версииВерсия исправления

< 2.0.33

2.0.33

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 5 лет назад

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

CVSS3: 7.5
redhat
около 5 лет назад

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

CVSS3: 7.5
nvd
почти 5 лет назад

A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.

CVSS3: 7.5
debian
почти 5 лет назад

A flaw was found in the Undertow AJP connector. Malicious requests and ...

EPSS

Процентиль: 40%
0.00182
Низкий

7.5 High

CVSS3

Дефекты

CWE-400