Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-14888

Опубликовано: 20 янв. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.

A vulnerability was found in the Undertow HTTP server listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.

Меры по смягчению последствий

Enable HTTP2 (enable-http2="true") in the undertow's HTTPS settings.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Decision Manager 7undertowNot affected
Red Hat JBoss Fuse 6undertowAffected
Red Hat OpenShift Application RuntimesundertowOut of support scope
Red Hat Process Automation 7undertowNot affected
Red Hat Single Sign-On 7undertowAffected
EAP-CD 19 Tech PreviewundertowFixedRHSA-2020:233328.05.2020
Red Hat Data Grid 7.3.5undertowFixedRHSA-2020:072905.03.2020
Red Hat Fuse 7.7.0undertowFixedRHSA-2020:319228.07.2020
Red Hat JBoss EAP 7.2undertow-coreFixedRHSA-2020:016421.01.2020
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7eap7-undertowFixedRHSA-2024:585626.08.2024

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1772464undertow: possible Denial Of Service (DOS) in Undertow HTTP server listening on HTTPS

EPSS

Процентиль: 46%
0.00235
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 6 лет назад

A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.

CVSS3: 7.5
nvd
около 6 лет назад

A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.

CVSS3: 7.5
debian
около 6 лет назад

A vulnerability was found in the Undertow HTTP server in versions befo ...

CVSS3: 7.5
github
больше 3 лет назад

Undertow vulnerable to Uncontrolled Resource Consumption

CVSS3: 7.5
fstec
около 6 лет назад

Уязвимость веб-сервера Undertow, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 46%
0.00235
Низкий

7.5 High

CVSS3