Описание
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
A vulnerability was found in the Undertow HTTP server listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
Меры по смягчению последствий
Enable HTTP2 (enable-http2="true") in the undertow's HTTPS settings.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Decision Manager 7 | undertow | Not affected | ||
| Red Hat JBoss Fuse 6 | undertow | Affected | ||
| Red Hat OpenShift Application Runtimes | undertow | Out of support scope | ||
| Red Hat Process Automation 7 | undertow | Not affected | ||
| Red Hat Single Sign-On 7 | undertow | Affected | ||
| EAP-CD 19 Tech Preview | undertow | Fixed | RHSA-2020:2333 | 28.05.2020 |
| Red Hat Data Grid 7.3.5 | undertow | Fixed | RHSA-2020:0729 | 05.03.2020 |
| Red Hat Fuse 7.7.0 | undertow | Fixed | RHSA-2020:3192 | 28.07.2020 |
| Red Hat JBoss EAP 7.2 | undertow-core | Fixed | RHSA-2020:0164 | 21.01.2020 |
| Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7 | eap7-undertow | Fixed | RHSA-2024:5856 | 26.08.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
A vulnerability was found in the Undertow HTTP server in versions before 2.0.28.SP1 when listening on HTTPS. An attacker can target the HTTPS port to carry out a Denial Of Service (DOS) to make the service unavailable on SSL.
A vulnerability was found in the Undertow HTTP server in versions befo ...
Undertow vulnerable to Uncontrolled Resource Consumption
Уязвимость веб-сервера Undertow, связанная с неконтролируемым расходом ресурса, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3