Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-3884

Опубликовано: 03 дек. 2025
Источник: redhat
EPSS Низкий

Описание

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.

Отчет

Red Hat rates this as a Moderate impact since this requires the use of a specific form method by the server that must be externally available and the input is not sanitized by the given servlet or class implementing its use.

Меры по смягчению последствий

It is possible to mitigate the vulnerability by performing an upper-level verification to ensure the content size sent server side is within the allowed parameters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift ServerlessundertowUnder investigation
Red Hat build of Apache Camel 4 for Quarkus 3undertowUnder investigation
Red Hat build of Apache Camel for Spring Boot 3undertowUnder investigation
Red Hat build of Apache Camel for Spring Boot 4undertowUnder investigation
Red Hat build of Apache Camel - HawtIO 4undertowUnder investigation
Red Hat build of Apicurio Registry 2undertowUnder investigation
Red Hat Build of KeycloakundertowUnder investigation
Red Hat build of OptaPlanner 8undertowUnder investigation
Red Hat build of Quarkusquarkus-undertowUnder investigation
Red Hat build of Quarkusquarkus-undertowUnder investigation

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2275287undertow: OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded

EPSS

Процентиль: 70%
0.01359
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
9 месяцев назад

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.

CVSS3: 7.5
nvd
9 месяцев назад

A flaw was found in Undertow that can cause remote denial of service attacks. When the server uses the FormEncodedDataDefinition.doParse(StreamSourceChannel) method to parse large form data encoding with application/x-www-form-urlencoded, the method will cause an OutOfMemory issue. This flaw allows unauthorized users to cause a remote denial of service (DoS) attack.

CVSS3: 7.5
debian
9 месяцев назад

A flaw was found in Undertow that can cause remote denial of service a ...

CVSS3: 7.5
github
9 месяцев назад

Undertow OutOfMemory when parsing form data encoding with application/x-www-form-urlencoded

EPSS

Процентиль: 70%
0.01359
Низкий