Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1973

Опубликовано: 04 апр. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2185662undertow: unrestricted request storage leads to memory exhaustion

EPSS

Процентиль: 68%
0.01284
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 2 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
nvd
почти 2 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
debian
почти 2 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMech ...

CVSS3: 7.5
github
почти 2 года назад

Undertow Denial of Service vulnerability

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость пакета Undertow программного обеспечения Red Hat JBoss Enterprise Application Platform, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 68%
0.01284
Низкий

7.5 High

CVSS3