Red Hat Undertow 2.2.19

CPE Details

Red Hat Undertow 2.2.19
2.2.19
2022-08-09
12h51 +00:00
2022-08-10
12h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:redhat:undertow:2.2.19:*:*:*:*:*:*:*

Informations

Vendor

redhat

Product

undertow

Version

2.2.19

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-3223 2023-09-27 13h54 +00:00 A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by setting the file name in the request to null.
7.5
High
CVE-2023-1108 2023-09-14 14h48 +00:00 A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
7.5
High
CVE-2022-2764 2022-08-31 22h00 +00:00 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
4.9
Medium
CVE-2022-1259 2022-08-30 22h00 +00:00 A flaw was found in Undertow. A potential security issue in flow control handling by the browser over HTTP/2 may cause overhead or a denial of service in the server. This flaw exists because of an incomplete fix for CVE-2021-3629.
7.5
High