CVE-2023-4639
- EPSS 3.74%
- Veröffentlicht 17.11.2024 11:15:05
- Zuletzt bearbeitet 07.02.2025 17:15:29
A flaw was found in Undertow, which incorrectly parses cookies with certain value-delimiting characters in incoming requests. This issue could allow an attacker to construct a cookie value to exfiltrate HttpOnly cookie values or spoof arbitrary addit...
CVE-2024-7885
- EPSS 6.4%
- Veröffentlicht 21.08.2024 14:15:09
- Zuletzt bearbeitet 25.09.2025 08:15:36
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection....
CVE-2023-44487
- EPSS 94.44%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-4492
- EPSS 0.12%
- Veröffentlicht 23.02.2023 20:15:12
- Zuletzt bearbeitet 12.03.2025 15:15:38
The undertow client is not checking the server identity presented by the server certificate in https connections. This is a compulsory step (at least it should be performed by default) in https and in http/2. I would add it to any TLS client protocol...
CVE-2022-2764
- EPSS 0.12%
- Veröffentlicht 01.09.2022 21:15:09
- Zuletzt bearbeitet 21.11.2024 07:01:39
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
CVE-2022-2053
- EPSS 0.53%
- Veröffentlicht 05.08.2022 16:15:11
- Zuletzt bearbeitet 21.11.2024 07:00:14
When a POST request comes through AJP and the request exceeds the max-post-size limit (maxEntitySize), Undertow's AjpServerRequestConduit implementation closes a connection without sending any response to the client/proxy. This behavior results in th...
CVE-2021-4104
- EPSS 72.2%
- Veröffentlicht 14.12.2021 12:15:12
- Zuletzt bearbeitet 21.11.2024 06:36:54
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppen...
CVE-2021-3642
- EPSS 0.27%
- Veröffentlicht 05.08.2021 21:15:13
- Zuletzt bearbeitet 21.11.2024 06:22:03
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
CVE-2020-14340
- EPSS 0.31%
- Veröffentlicht 02.06.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 05:03:02
A vulnerability was discovered in XNIO where file descriptor leak caused by growing amounts of NIO Selector file handles between garbage collection cycles. It may allow the attacker to cause a denial of service. It affects XNIO versions 3.6.0.Beta1 t...
CVE-2021-20218
- EPSS 0.59%
- Veröffentlicht 16.03.2021 21:15:10
- Zuletzt bearbeitet 21.11.2024 05:46:09
A flaw was found in the fabric8 kubernetes-client in version 4.2.0 and after. This flaw allows a malicious pod/container to cause applications using the fabric8 kubernetes-client `copy` command to extract files outside the working path. The highest t...