Описание
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apicurio Registry 2 | undertow | Affected | ||
| Red Hat build of Quarkus | io.quarkus/quarkus-undertow | Not affected | ||
| Red Hat Data Grid 8 | undertow | Not affected | ||
| Red Hat Integration Camel K 1 | undertow | Affected | ||
| Red Hat Integration Camel Quarkus 1 | undertow | Not affected | ||
| Red Hat JBoss Data Grid 7 | undertow | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform Expansion Pack | undertow | Affected | ||
| Red Hat JBoss Fuse 6 | undertow | Out of support scope | ||
| Red Hat OpenStack Platform 13 (Queens) | undertow | Affected | ||
| Red Hat Fuse 7.12 | undertow | Fixed | RHSA-2023:3954 | 29.06.2023 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
A flaw was found in undertow. This issue makes achieving a denial of s ...
Уязвимость веб-сервера Undertow, связанная с выполнением цикла с недоступным условием выхода, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3