Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-14384

Опубликовано: 03 сент. 2020
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

A flaw was found in jbossweb. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example. Please update as soon as possible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Grid 6jbosswebOut of support scope
Red Hat JBoss Data Virtualization 6jbosswebOut of support scope
EAP 6.4.24 releaseFixedRHSA-2022:545830.06.2022
Red Hat JBoss Enterprise Application Platform 6.4jbosswebFixedRHSA-2020:373114.09.2020
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 5jbosswebFixedRHSA-2020:373014.09.2020
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6jbosswebFixedRHSA-2020:373014.09.2020
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6jboss-as-appclientFixedRHSA-2022:545930.06.2022
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6jbossas-appclientFixedRHSA-2022:545930.06.2022
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6jbossas-bundlesFixedRHSA-2022:545930.06.2022
Red Hat JBoss Enterprise Application Platform 6.4 for RHEL 6jboss-as-cliFixedRHSA-2022:545930.06.2022

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1875176jbossweb: Incomplete fix of CVE-2020-13935 for WebSocket in JBossWeb could lead to DoS

EPSS

Процентиль: 55%
0.00325
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

github
больше 3 лет назад

A flaw was found in JBossWeb in versions before 7.5.31.Final-redhat-3. The fix for CVE-2020-13935 was incomplete in JBossWeb, leaving it vulnerable to a denial of service attack when sending multiple requests with invalid payload length in a WebSocket frame. The highest threat from this vulnerability is to system availability.

EPSS

Процентиль: 55%
0.00325
Низкий

7.5 High

CVSS3