Description
A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1173 | A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow 2.1.5.SP1, 2.0.33.SP2, and 2.2.3.SP1. |
Github GHSA |
GHSA-rhcw-wjcm-9h6g | Denial of service in Undertow |
References
History
Wed, 25 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T16:25:42.926Z
Reserved: 2020-10-27T00:00:00.000Z
Link: CVE-2020-27782
No data.
Status : Modified
Published: 2021-02-23T19:15:13.150
Modified: 2024-11-21T05:21:49.550
Link: CVE-2020-27782
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA