Description
A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3227 | A flaw was found in Undertow package. Using the FormAuthenticationMechanism, a malicious user could trigger a Denial of Service by sending crafted requests, leading the server to an OutofMemory error, exhausting the server's memory. |
Github GHSA |
GHSA-97cq-f4jm-mv8h | Undertow Denial of Service vulnerability |
References
History
Wed, 25 Jun 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.3::el7 |
Mon, 28 Apr 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat jboss Enterprise Application Platform Eus
|
|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform_eus:7.1::el7 | |
| Vendors & Products |
Redhat jboss Enterprise Application Platform Eus
|
Thu, 07 Nov 2024 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 07 Nov 2024 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | undertow: unrestricted request storage leads to memory exhaustion | Undertow: unrestricted request storage leads to memory exhaustion |
| References |
|
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-11-07T14:06:43.345Z
Reserved: 2023-04-10T23:29:16.249Z
Link: CVE-2023-1973
Updated: 2024-11-07T14:06:39.564Z
Status : Awaiting Analysis
Published: 2024-11-07T10:15:05.400
Modified: 2024-11-08T19:01:03.880
Link: CVE-2023-1973
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA