A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Netapp
Subscribe
|
Oncommand Workflow Automation
Subscribe
|
|
Redhat
Subscribe
|
Build Of Quarkus
Subscribe
Camel Quarkus
Subscribe
Decision Manager
Subscribe
Enterprise Linux
Subscribe
Fuse
Subscribe
Integration
Subscribe
Integration Camel K
Subscribe
Integration Service Registry
Subscribe
Jboss Data Grid
Subscribe
Jboss Enterprise Application Platform
Subscribe
Jboss Enterprise Application Platform Eus
Subscribe
Jboss Enterprise Application Platform Expansion Pack
Subscribe
Jboss Enterprise Bpms Platform
Subscribe
Jboss Fuse
Subscribe
Jbosseapxp
Subscribe
Openshift Application Runtimes
Subscribe
Openshift Container Platform
Subscribe
Openshift Container Platform For Linuxone
Subscribe
Openshift Container Platform For Power
Subscribe
Openstack
Subscribe
Openstack Platform
Subscribe
Process Automation
Subscribe
Quarkus
Subscribe
Red Hat Single Sign On
Subscribe
Rhosemc
Subscribe
Service Registry
Subscribe
Single Sign-on
Subscribe
Undertow
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2542 | A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates. |
Github GHSA |
GHSA-m4mm-pg93-fv78 | Undertow denial of service vulnerability |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 25 Jun 2025 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 28 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-02T05:32:46.370Z
Reserved: 2023-03-01T00:27:23.587Z
Link: CVE-2023-1108
Updated: 2024-08-02T05:32:46.370Z
Status : Modified
Published: 2023-09-14T15:15:08.293
Modified: 2024-11-21T07:38:28.330
Link: CVE-2023-1108
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA