Undertow Vulnerability: Enabling Learning-Push Handler Can Prevent Attacks

CVE-2024-3653
5.3MEDIUM

Key Information

Vendor
Red Hat
Status
Red Hat Jboss Enterprise Application Platform 7.1.0
Red Hat Jboss Enterprise Application Platform 7.4 For Rhel 8
Red Hat Jboss Enterprise Application Platform 7.4 For Rhel 9
Red Hat Jboss Enterprise Application Platform 7.4 On Rhel 7
Vendor
CVE Published:
8 July 2024

Summary

A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.

Affected Version(s)

Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 <= 0:2.2.33-1.SP1_redhat_00001.1.el8eap

Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 <= 0:2.2.33-1.SP1_redhat_00001.1.el9eap

Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 <= 0:2.2.33-1.SP1_redhat_00001.1.el7eap

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: null to: 5.3 - (MEDIUM)

  • Vulnerability published.

  • Vulnerability Reserved.

  • Reported to Red Hat.

Collectors

NVD DatabaseMitre Database
.