Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2452 | A vulnerability was found in Undertow, where the chunked response hangs after the body was flushed. The response headers and body were sent but the client would continue waiting as Undertow does not send the expected 0\r\n termination of the chunked response. This results in uncontrolled resource consumption, leaving the server side to a denial of service attack. This happens only with Java 17 TLSv1.3 scenarios. |
Github GHSA |
GHSA-xpp6-8r3j-ww43 | Undertow Denial of Service vulnerability |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Mon, 01 Sep 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7 |
Wed, 25 Jun 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs |
Tue, 24 Jun 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4::el6 |
Wed, 18 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat apache Camel Hawtio
|
|
| CPEs | cpe:/a:redhat:apache_camel_hawtio:4 | |
| Vendors & Products |
Redhat rhboac Hawtio
|
Redhat apache Camel Hawtio
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 19 Sep 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
|
| Metrics |
ssvc
|
Thu, 19 Sep 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:3.20.7 | |
| References |
|
Wed, 18 Sep 2024 07:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:build_keycloak: |
Mon, 09 Sep 2024 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:apache_camel_spring_boot:4.4.2 | |
| References |
|
Thu, 29 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 08 Aug 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:/a:redhat:jboss_enterprise_application_platform:7.4 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el7 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el8 cpe:/a:redhat:jboss_enterprise_application_platform:7.4::el9 |
|
| References |
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-07T20:40:28.397Z
Reserved: 2024-06-13T13:50:13.855Z
Link: CVE-2024-5971
Updated: 2024-08-28T15:02:51.331Z
Status : Awaiting Analysis
Published: 2024-07-08T21:15:12.480
Modified: 2024-11-21T09:48:40.127
Link: CVE-2024-5971
OpenCVE Enrichment
No data.
EUVD
Github GHSA