A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed. As a result, the server may attempt to access the wrong path, causing errors such as "404 Not Found" or other application failures. This flaw can potentially lead to a denial of service, as legitimate resources become inaccessible due to the path mix-up.
History

Thu, 19 Sep 2024 08:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Sep 2024 08:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:build_keycloak:22 cpe:/a:redhat:build_keycloak:

Mon, 09 Sep 2024 18:00:00 +0000


Mon, 09 Sep 2024 10:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:jboss_enterprise_application_platform:8.0

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2024-06-20T14:33:10.342Z

Updated: 2024-11-15T21:04:35.335Z

Reserved: 2024-06-19T12:35:30.284Z

Link: CVE-2024-6162

cve-icon Vulnrichment

Updated: 2024-08-01T21:33:05.087Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-06-20T15:15:50.570

Modified: 2024-09-09T18:15:04.023

Link: CVE-2024-6162

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-06-19T00:00:00Z

Links: CVE-2024-6162 - Bugzilla