VDB
BDU%3A2024-08258
BDU%3A2024-08258
PUBLISHED
CVSS 7.800000190734863 HIGH
Уязвимость класса AjpRequestParser компонента ajp-listener веб-сервера Undertow, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 2.0
7.800000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat Inc., Oracle Corp. | Red Hat Single Sign-On, Red Hat JBoss Data Grid, Red Hat Process Automation, Red Hat Integration Camel K, Red Hat JBoss Enterprise Application Platform Expansion Pack, Red Hat build of Apache Camel for Spring Boot, undertow, Oracle Communications Cloud Native Core Certificate Management, Oracle Communications Cloud Native Core Unified Data Repository, Red Hat JBoss Enterprise Application Platform, Red Hat Fuse |
Timeline
- Oct 21, 2024 CVE Published
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
- Mar 19, 2026 Distribution Patch
References
- https://github.com/undertow-io/undertow/releases/tag/2.3.14.Final url
- https://github.com/undertow-io/undertow/releases/tag/2.2.33.Final url
- https://access.redhat.com/errata/RHSA-2024:1194 url
- https://access.redhat.com/errata/RHSA-2024:4386 url
- https://access.redhat.com/errata/RHSA-2024:4884 url
- https://access.redhat.com/security/cve/CVE-2024-6162 url
- https://bugzilla.redhat.com/show_bug.cgi?id=2293069 url
- https://issues.redhat.com/browse/JBEAP-26268 url
- https://issues.redhat.com/browse/UNDERTOW-2334 url
- https://www.cybersecurity-help.cz/vdb/SB2024062415 url
- https://undertow.io/javadoc/1.3.x/io/undertow/server/protocol/ajp/AjpRequestParser.html url
- https://github.com/undertow-io/undertow/pull/1612 url
- https://github.com/undertow-io/undertow/pull/1609 url
- https://issues.redhat.com/browse/WFCORE-6862 url
- https://github.com/advisories/GHSA-9442-gm4v-r222 advisory
- https://www.oracle.com/security-alerts/cpuoct2024.html?534662 advisory