A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HNetapp Oncommand Workflow Automation
APPNetappwszystkie wersjeRed Hat Build Of Quarkus
APPRedhatwszystkie wersjeRed Hat Decision Manager
APPRedhat7.0Red Hat Enterprise Linux
OSRedhat7.08.09.0Red Hat Fuse
APPRedhat1.0.0Red Hat Integration Camel K
APPRedhatwszystkie wersjeRed Hat Integration Service Registry
APPRedhatwszystkie wersjeRed Hat Jboss Enterprise Application Platform
APPRedhat7.4Red Hat Jboss Enterprise Application Platform Expansion Pack
APPRedhatwszystkie wersjeRed Hat Openshift Application Runtimes
APPRedhatwszystkie wersjeRed Hat OpenShift Container Platform
APPRedhat4.114.12Red Hat Openshift Container Platform For Linuxone
APPRedhat4.104.9Red Hat Openshift Container Platform For Power
APPRedhat4.104.9Red Hat Openstack Platform
APPRedhat13.0Red Hat Process Automation
APPRedhat7.0Red Hat Single Sign On
APPRedhat7.6Red Hat Undertow
APPRedhat< 2.2.242.3.0 – 2.3.5 (bez)
🟢
PATCH DOSTĘPNY
Aktualizacja od producenta gotowa. Wdrożenie w ramach standardowego cyklu.
Tagi
DoS
Referencje
Powiązane podatności
CVE-2025-32463CRITICAL9.3⚠ KEVPL ✓ten sam produkt
Sudo: eskalacja uprawnień do root poprzez opcję --chroot (CVE-2025-32463)
CVE-2021-40438CRITICAL9.0⚠ KEVPL ✓ten sam produkt
SSRF w mod_proxy Apache HTTP Server — przekierowanie żądań przez atakującego
CVE-2019-7609CRITICAL10.0⚠ KEVPL ✓ten sam produkt
RCE w Kibana Timelion — wykonanie kodu z uprawnieniami procesu
CVE-2019-1003029CRITICAL9.9⚠ KEVPL ✓ten sam produkt
Jenkins Script Security Plugin — sandbox bypass umożliwiający RCE
CVE-2019-1003030CRITICAL9.9⚠ KEVPL ✓ten sam produkt
Jenkins Pipeline Groovy Plugin — bypass sandbox i wykonanie kodu (RCE)