Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-2670

Опубликовано: 07 июн. 2017
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

It was found that with non-clean TCP close, Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7karafAffected
Red Hat JBoss Data Grid 7undertowAffected
Red Hat JBoss Fuse 6karafWill not fix
Red Hat JBoss Fuse Integration Service 2undertowAffected
Red Hat Single Sign-On 7wildflyAffected
Red Hat JBoss Data Grid 7.1FixedRHSA-2017:324416.11.2017
Red Hat JBoss EAP 7FixedRHSA-2017:140907.06.2017
Red Hat JBoss EAP 7FixedRHSA-2017:345613.12.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-activemq-artemisFixedRHSA-2017:141007.06.2017
Red Hat JBoss Enterprise Application Platform 7.0 for RHEL 6eap7-apache-cxfFixedRHSA-2017:141007.06.2017

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=1438885undertow: IO thread DoS via unclean Websocket closing

EPSS

Процентиль: 90%
0.05972
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

CVSS3: 7.5
nvd
больше 7 лет назад

It was found in Undertow before 1.3.28 that with non-clean TCP close, the Websocket server gets into infinite loop on every IO thread, effectively causing DoS.

CVSS3: 7.5
debian
больше 7 лет назад

It was found in Undertow before 1.3.28 that with non-clean TCP close, ...

CVSS3: 7.5
github
больше 7 лет назад

Moderate severity vulnerability that affects io.undertow:undertow-core

EPSS

Процентиль: 90%
0.05972
Низкий

7.5 High

CVSS3

Уязвимость CVE-2017-2670