Undertow Vulnerability: Enabling Learning-Push Handler Can Prevent Attacks
CVE-2024-3653
Key Information
- Vendor
- Red Hat
- Status
- Red Hat Jboss Enterprise Application Platform 7.1.0
- Red Hat Jboss Enterprise Application Platform 7.4 For Rhel 8
- Red Hat Jboss Enterprise Application Platform 7.4 For Rhel 9
- Red Hat Jboss Enterprise Application Platform 7.4 On Rhel 7
- Vendor
- CVE Published:
- 8 July 2024
Summary
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 <= 0:2.2.33-1.SP1_redhat_00001.1.el8eap
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 <= 0:2.2.33-1.SP1_redhat_00001.1.el9eap
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 <= 0:2.2.33-1.SP1_redhat_00001.1.el7eap
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved