VDB
BDU%3A2024-07803
BDU%3A2024-07803
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость функции parseProxyProtocolV1() класса ProxyProtocolReadListener веб-сервера Undertow, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc. | Red Hat Single Sign-On, Red Hat JBoss Enterprise Application Platform, Red Hat Build of Keycloak, undertow, Red Hat build of Apache Camel |
Timeline
- Oct 7, 2024 CVE Published
- Jun 3, 2025 CVE Updated
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2305290 url
- https://access.redhat.com/security/cve/CVE-2024-7885 url
- https://github.com/advisories/GHSA-9623-mqmm-5rcf url
- https://vuldb.com/ru/?id.275132 url
- https://github.com/undertow-io/undertow/pull/1648 url
- https://github.com/undertow-io/undertow/blob/2.3.17.Final/core/src/main/java/io/undertow/server/protocol/proxy/ProxyProtocolReadListener.java advisory
- https://github.com/undertow-io/undertow/commit/80c125e09068ac52ed0a9acde266ef12f8ed7ae1 advisory