Remote Denial of Service Vulnerability in Undertow by Red Hat
CVE-2024-3884
Key Information:
What is CVE-2024-3884?
A vulnerability exists in Undertow, a web server framework developed by Red Hat, that enables unauthorized users to execute remote denial of service attacks. This flaw arises when the server's FormEncodedDataDefinition.doParse(StreamSourceChannel) method is called to handle excessively large form data encoded in application/x-www-form-urlencoded format. The result is an OutOfMemory error, making it possible for an attacker to disrupt service availability. Organizations utilizing Undertow are encouraged to assess their configurations and manage input sizes to mitigate potential exploitation risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 8 0:2.3.20-2.SP4_redhat_00001.1.el8eap
Red Hat JBoss Enterprise Application Platform 8.1 for RHEL 9 0:2.3.20-2.SP4_redhat_00001.1.el9eap
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved