A flaw was found in Undertow when using Remoting as shipped in Red Hat Jboss EAP before version 7.2.4. A memory leak in HttpOpenListener due to holding remote connections indefinitely may lead to denial of service. Versions before undertow 2.0.25.SP1 and jboss-remoting 5.0.14.SP1 are believed to be vulnerable.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-03-23T20:23:20

Updated: 2024-08-05T02:16:46.887Z

Reserved: 2019-11-27T00:00:00

Link: CVE-2019-19343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-03-23T21:15:13.417

Modified: 2024-11-21T04:34:36.973

Link: CVE-2019-19343

cve-icon Redhat

Severity : Moderate

Publid Date: 2019-12-06T00:00:00Z

Links: CVE-2019-19343 - Bugzilla