Description
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2542 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
Github GHSA |
GHSA-m4mm-pg93-fv78 | Undertow denial of service vulnerability |
References
History
Fri, 27 Feb 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Jun 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 28 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Subscriptions
Netapp
Subscribe
Oncommand Workflow Automation
Subscribe
Redhat
Subscribe
Build Of Quarkus
Subscribe
Camel Quarkus
Subscribe
Decision Manager
Subscribe
Enterprise Linux
Subscribe
Fuse
Subscribe
Integration
Subscribe
Integration Camel K
Subscribe
Integration Service Registry
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Enterprise Application Platform Expansion Pack
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Openshift Application Runtimes
Subscribe
Openshift Container Platform
Subscribe
Openshift Container Platform For Linuxone
Subscribe
Openshift Container Platform For Power
Subscribe
Openstack
Subscribe
Openstack Platform
Subscribe
Process Automation
Subscribe
Quarkus
Subscribe
Red Hat Single Sign On
Subscribe
Rhosemc
Subscribe
Service Registry
Subscribe
Single Sign-on
Subscribe
Undertow
Subscribe
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-02T05:32:46.370Z
Reserved: 2023-03-01T00:27:23.587Z
Link: CVE-2023-1108
Updated: 2024-08-02T05:32:46.370Z
Status : Modified
Published: 2023-09-14T15:15:08.293
Modified: 2024-11-21T07:38:28.330
Link: CVE-2023-1108
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA