跳转到帖子

Red Hat JBossEAP: Uncontrolled Recursion (CVE-2024-5971)

recommended_posts

发布于
  • Members

Red Hat JBossEAP: Uncontrolled Recursion (CVE-2024-5971)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
07/08/2024
Created
09/20/2024
Added
09/19/2024
Modified
12/20/2024

Description

A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.. A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios.

Solution(s)

  • red-hat-jboss-eap-upgrade-latest

References

  • https://attackerkb.com/topics/cve-2024-5971
  • CVE - 2024-5971
  • https://access.redhat.com/security/cve/CVE-2024-5971
  • https://bugzilla.redhat.com/show_bug.cgi?id=2292211
  • https://access.redhat.com/errata/RHSA-2024:4392
  • https://access.redhat.com/errata/RHSA-2024:5143
  • https://access.redhat.com/errata/RHSA-2024:5144
  • https://access.redhat.com/errata/RHSA-2024:5145
  • https://access.redhat.com/errata/RHSA-2024:5147
View more
  • 查看数 701
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。

游客
回帖…