CVE Vulnerabilities

CVE-2023-1108

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 14, 2023 | Modified: May 03, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Build_of_quarkus Redhat - (including) - (including)
Decision_manager Redhat 7.0 (including) 7.0 (including)
Fuse Redhat 1.0.0 (including) 1.0.0 (including)
Integration_camel_k Redhat - (including) - (including)
Integration_service_registry Redhat - (including) - (including)
Jboss_enterprise_application_platform Redhat - (including) - (including)
Jboss_enterprise_application_platform_expansion_pack Redhat - (including) - (including)
Openshift_application_runtimes Redhat - (including) - (including)
Openstack_platform Redhat 13.0 (including) 13.0 (including)
Process_automation Redhat 7.0 (including) 7.0 (including)
Single_sign-on Redhat - (including) - (including)
Undertow Redhat * 2.2.24 (excluding)
Undertow Redhat 2.3.0 (including) 2.3.5 (excluding)
EAP 7.4.10 release RedHat *
Red Hat Fuse 7.12 RedHat undertow *
Red Hat JBoss Enterprise Application Platform 7 RedHat undertow *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9 RedHat eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el9eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-undertow-0:2.2.22-1.SP3_redhat_00002.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-wildfly-0:7.4.9-6.GA_redhat_00004.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-undertow-0:2.2.23-1.SP2_redhat_00001.1.el7eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-undertow-jastow-0:2.0.14-1.Final_redhat_00001.1.el7eap *
Red Hat Single Sign-On 7 RedHat undertow *
Red Hat Single Sign-On 7.6 for RHEL 7 RedHat rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el7sso *
Red Hat Single Sign-On 7.6 for RHEL 8 RedHat rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el8sso *
Red Hat Single Sign-On 7.6 for RHEL 9 RedHat rh-sso7-keycloak-0:18.0.8-1.redhat_00001.1.el9sso *
Red Hat support for Spring Boot 2.7.13 RedHat undertow *
RHEL-8 based Middleware Containers RedHat rh-sso-7/sso76-openshift-rhel8:7.6-24 *
RHPAM 7.13.1 async RedHat undertow *
Undertow Ubuntu bionic *
Undertow Ubuntu kinetic *
Undertow Ubuntu trusty *
Undertow Ubuntu xenial *

References