Описание
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
A flaw was discovered in Undertow where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
Меры по смягчению последствий
There is currently no known mitigation for this security flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Decision Manager 7 | undertow | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | jbossweb | Not affected | ||
| Red Hat OpenShift Application Runtimes | undertow | Affected | ||
| Red Hat Process Automation 7 | undertow | Not affected | ||
| EAP-CD 20 Tech Preview | undertow | Fixed | RHSA-2020:3585 | 31.08.2020 |
| Red Hat JBoss EAP 7 | Fixed | RHSA-2020:2515 | 10.06.2020 | |
| Red Hat JBoss EAP 7.2 | undertow-core | Fixed | RHSA-2020:2061 | 11.05.2020 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-activemq-artemis | Fixed | RHSA-2020:2058 | 11.05.2020 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-apache-cxf | Fixed | RHSA-2020:2058 | 11.05.2020 |
| Red Hat JBoss Enterprise Application Platform 7.2 for RHEL 6 | eap7-bouncycastle | Fixed | RHSA-2020:2058 | 11.05.2020 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Final where certain requests to the "Expect: 100-continue" header may cause an out of memory error. This flaw may potentially lead to a denial of service.
A flaw was discovered in Undertow in versions before Undertow 2.1.1.Fi ...
Allocation of Resources Without Limits or Throttling in Undertow
EPSS
7.5 High
CVSS3