Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-1973

Опубликовано: 04 апр. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

Дополнительная информация

Статус:

Important
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2185662undertow: unrestricted request storage leads to memory exhaustion

EPSS

Процентиль: 72%
0.00727
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
nvd
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.

CVSS3: 7.5
debian
больше 1 года назад

A flaw was found in Undertow package. Using the FormAuthenticationMech ...

CVSS3: 7.5
github
больше 1 года назад

Undertow Denial of Service vulnerability

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость пакета Undertow программного обеспечения Red Hat JBoss Enterprise Application Platform, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 72%
0.00727
Низкий

7.5 High

CVSS3