CVE Vulnerabilities

CVE-2022-2764

Published: Sep 01, 2022 | Modified: Nov 07, 2022
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.

Affected Software

Name Vendor Start Version End Version
Integration_camel_k Redhat - (including) - (including)
Jboss_enterprise_application_platform Redhat 7.0.0 (including) 7.0.0 (including)
Jboss_fuse Redhat 7.0.0 (including) 7.0.0 (including)
Single_sign-on Redhat 7.0 (including) 7.0 (including)
Undertow Redhat 2.0.0 (including) 2.2.19 (including)
Undertow Redhat 2.3.0-alpha1 (including) 2.3.0-alpha1 (including)
Undertow Redhat 2.3.0-alpha2 (including) 2.3.0-alpha2 (including)

References