跳转到帖子

Red Hat JBossEAP: Uncontrolled Resource Consumption (CVE-2024-6162)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Uncontrolled Resource Consumption (CVE-2024-6162)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
06/19/2024
Created
09/20/2024
Added
09/19/2024
Modified
12/20/2024

Description

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.. A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-6162
  • CVE - 2024-6162
  • https://access.redhat.com/security/cve/CVE-2024-6162
  • https://bugzilla.redhat.com/show_bug.cgi?id=2293069
  • https://issues.redhat.com/browse/JBEAP-26268
  • https://access.redhat.com/errata/RHSA-2024:1194
  • 查看数 720
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…