Remote Denial of Service Vulnerability in Undertow by Red Hat
CVE-2024-3884

7.5HIGH

What is CVE-2024-3884?

A vulnerability exists in Undertow, a web server framework developed by Red Hat, that enables unauthorized users to execute remote denial of service attacks. This flaw arises when the server's FormEncodedDataDefinition.doParse(StreamSourceChannel) method is called to handle excessively large form data encoded in application/x-www-form-urlencoded format. The result is an OutOfMemory error, making it possible for an attacker to disrupt service availability. Organizations utilizing Undertow are encouraged to assess their configurations and manage input sizes to mitigate potential exploitation risks.

Affected Version(s)

Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 0:2.0.2-2.redhat_00002.1.el8eap

Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 0:2.16.1-2.redhat_00002.1.el8eap

Red Hat JBoss Enterprise Application Platform 8.0 for RHEL 8 0:2.0.1-5.redhat_00007.1.el8eap

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-3884 : Remote Denial of Service Vulnerability in Undertow by Red Hat