A flaw was found in Undertow. A buffer leak on the incoming WebSocket PONG message may lead to memory exhaustion. This flaw allows an attacker to cause a denial of service. The highest threat from this vulnerability is availability.
2022-08-23T16:15:09.450
2024-11-21T06:22:09.833
Modified
CVSSv3.1: 7.5 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | redhat | fuse | 1.0 | Yes |
Application | redhat | integration_camel_k | - | Yes |
Application | redhat | integration_camel_quarkus | - | Yes |
Application | redhat | jboss_enterprise_application_platform | - | Yes |
Application | redhat | openshift_application_runtimes | - | Yes |
Application | redhat | single_sign-on | - | Yes |
Application | redhat | undertow | < 2.0.40 | Yes |
Application | redhat | undertow | < 2.2.10 | Yes |
Application | redhat | jboss_enterprise_application_platform | 7.3 | Yes |
Operating System | redhat | enterprise_linux | 6.0 | No |
Operating System | redhat | enterprise_linux | 7.0 | No |
Operating System | redhat | enterprise_linux | 8.0 | No |
Application | redhat | jboss_enterprise_application_platform | 7.4 | Yes |
Operating System | redhat | enterprise_linux | 7.0 | No |
Operating System | redhat | enterprise_linux | 8.0 | No |