Описание
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
Отчет
Red Hat rates this as a Moderate impact since this requires the use of a specific form method by the server that must be externally available and the input is not sanitized by the given servlet or class implementing its use.
Меры по смягчению последствий
It is possible to mitigate the vulnerability by performing an upper-level verification to ensure the content size sent server side is within the allowed parameters.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Serverless | undertow | Under investigation | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | undertow | Under investigation | ||
| Red Hat build of Apache Camel for Spring Boot 3 | undertow | Under investigation | ||
| Red Hat build of Apache Camel for Spring Boot 4 | undertow | Under investigation | ||
| Red Hat build of Apache Camel - HawtIO 4 | undertow | Under investigation | ||
| Red Hat build of Apicurio Registry 2 | undertow | Under investigation | ||
| Red Hat Build of Keycloak | undertow | Under investigation | ||
| Red Hat build of OptaPlanner 8 | undertow | Under investigation | ||
| Red Hat build of Quarkus | quarkus-undertow | Under investigation | ||
| Red Hat build of Quarkus | quarkus-undertow | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
Связанные уязвимости
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.
A flaw was found in Undertow that can cause remote denial of service a ...
Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded
EPSS