CVE-2018-1114 PUBLISHED

It was found that URLResource.getLastModified() in Undertow closes the file descriptors only when they are finalized which can cause file descriptors to exhaust. This leads to a file handler leak.

EPSS 0.71% · 72.0th percentile

Risk Scores

EPSS Score
0.71%
72.0th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSundertow0, 2.0.29-1, 2.0.28-1
Ubuntu:24.04:LTSundertow2.3.8-2, 0
Ubuntu:16.04:LTSundertow1.3.16-1, 1.3.11-1, 1.3.7-1
Ubuntu:22.04:LTSundertow0, 2.2.12-1, 2.2.13-1
Ubuntu:18.04:LTSundertow0, 1.4.21-1, 1.4.22-1

Timeline

References

Open in Interactive Console →