Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1108


A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.


Published

2023-09-14T15:15:08.293

Last Modified

2024-11-21T07:38:28.330

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-835
  • Type: Primary
    CWE-835

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application redhat build_of_quarkus - Yes
Application redhat decision_manager 7.0 Yes
Application redhat fuse 1.0.0 Yes
Application redhat integration_camel_k - Yes
Application redhat integration_service_registry - Yes
Application redhat jboss_enterprise_application_platform - Yes
Application redhat jboss_enterprise_application_platform_expansion_pack - Yes
Application redhat openshift_application_runtimes - Yes
Application redhat openstack_platform 13.0 Yes
Application redhat process_automation 7.0 Yes
Application redhat single_sign-on - Yes
Application redhat undertow < 2.2.24 Yes
Application redhat undertow < 2.3.5 Yes
Application redhat openshift_container_platform 4.11 Yes
Application redhat openshift_container_platform 4.12 Yes
Application redhat openshift_container_platform_for_linuxone 4.9 Yes
Application redhat openshift_container_platform_for_linuxone 4.10 Yes
Application redhat openshift_container_platform_for_power 4.9 Yes
Application redhat openshift_container_platform_for_power 4.10 Yes
Operating System redhat enterprise_linux 8.0 No
Application redhat jboss_enterprise_application_platform 7.4 Yes
Operating System redhat enterprise_linux 7.0 No
Operating System redhat enterprise_linux 8.0 No
Operating System redhat enterprise_linux 9.0 No
Application redhat single_sign-on 7.6 Yes
Operating System redhat enterprise_linux 7.0 No
Operating System redhat enterprise_linux 8.0 No
Operating System redhat enterprise_linux 9.0 No
Application netapp oncommand_workflow_automation - Yes

References