CVE-2023-1108
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.
Affected (22)
Products: Redhat: Build Of Quarkus, Decision Manager, Fuse, Integration Camel K, Integration Service Registry, Jboss Enterprise Application Platform, Jboss Enterprise Application Platform Expansion Pack, Openshift Application Runtimes, Openstack Platform, Process Automation, Single Sign On, Undertow, Openshift Container Platform, Openshift Container Platform For Linuxone, Openshift Container Platform For Power · Netapp: Oncommand Workflow Automation
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| Version 7.0 | |
| Version 1.0.0 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 13.0 | |
| Version 7.0 | |
| All versions | |
| Before 2.2.24 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 4.11 | |
| Version 4.10 | |
| Version 4.10 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.4 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.6 |
| Running on/with | Platform Versions |
|---|---|
Redhat Enterprise Linux | Version 7.0 |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (36)
Source: secalert@redhat.com
Source: secalert@redhat.com
Source: secalert@redhat.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Timeline
No history available yet.