Описание
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
Меры по смягчению последствий
To mitigate this issue, configure the PerMessageDeflateHandshake to limit the maximum decompressed buffer size. This can be achieved by setting the maxDecompressedBufferSize parameter to a reasonable value (e.g., 10 MB) in the PerMessageDeflateHandshake constructor. This action may require a restart of the affected application or service to take effect.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 4 | undertow-core | Affected | ||
| Red Hat build of Apache Camel - HawtIO 4 | undertow-core | Not affected | ||
| Red Hat Data Grid 8 | undertow-core | Affected | ||
| Red Hat Enterprise Linux 10 | moditect | Not affected | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Affected | ||
| Red Hat Enterprise Linux 8 | pki-deps:10.6/resteasy | Not affected | ||
| Red Hat Enterprise Linux 9 | resteasy | Affected | ||
| Red Hat Fuse 7 | undertow-core | Affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | undertow-core | Will not fix | ||
| Red Hat JBoss Enterprise Application Platform 8 | undertow-core | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
A flaw was found in Undertow. A remote attacker could exploit this vul ...
A flaw was found in Undertow. A remote attacker could exploit this vulnerability by sending specially crafted WebSocket messages with permessage-deflate negotiated. This could lead to excessive memory consumption due to the PerMessageDeflateFunction.largerBuffer() method using exponential doubling, resulting in a Denial of Service (DoS) for the affected application.
7.5 High
CVSS3