Описание
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
Отчет
Red Hat rates this issue as an important impact since a malicious user may benefit from causing Denial of Service (DoS) to the server by sending large post requests as application/x-www-form-urlencoded or multipart/form-data, causing the parsing to run an OutOfMemoryError.
Меры по смягчению последствий
Currently no mitigation is available for this vulnerability. Please make sure to perform the update as they become available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Serverless | undertow | Under investigation | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | undertow | Under investigation | ||
| Red Hat build of Apache Camel for Spring Boot 3 | undertow | Under investigation | ||
| Red Hat build of Apache Camel for Spring Boot 4 | undertow | Under investigation | ||
| Red Hat build of Apache Camel - HawtIO 4 | undertow | Under investigation | ||
| Red Hat build of Apicurio Registry 2 | undertow | Affected | ||
| Red Hat Build of Keycloak | undertow | Under investigation | ||
| Red Hat build of OptaPlanner 8 | undertow | Under investigation | ||
| Red Hat build of Quarkus | quarkus-undertow | Out of support scope | ||
| Red Hat build of Quarkus | quarkus-undertow | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
A flaw was found in Undertow. Servlets using a method that calls HttpServletRequestImpl.getParameterNames() can cause an OutOfMemoryError when the client sends a request with large parameter names. This issue can be exploited by an unauthorized user to cause a remote denial-of-service (DoS) attack.
A flaw was found in Undertow. Servlets using a method that calls HttpS ...
Undertow Servlets Vulnerable to Remote DoS via OutOfMemoryError when Passed Large Parameter Names
EPSS
7.5 High
CVSS3