CVE Vulnerabilities

CVE-2023-1108

Loop with Unreachable Exit Condition ('Infinite Loop')

Published: Sep 14, 2023 | Modified: May 03, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw was found in undertow. This issue makes achieving a denial of service possible due to an unexpected handshake status updated in SslConduit, where the loop never terminates.

Weakness

The product contains an iteration or loop with an exit condition that cannot be reached, i.e., an infinite loop.

Affected Software

Name Vendor Start Version End Version
Build_of_quarkus Redhat - (including) - (including)
Decision_manager Redhat 7.0 (including) 7.0 (including)
Fuse Redhat 1.0.0 (including) 1.0.0 (including)
Integration_camel_k Redhat - (including) - (including)
Integration_service_registry Redhat - (including) - (including)
Jboss_enterprise_application_platform Redhat - (including) - (including)
Jboss_enterprise_application_platform_expansion_pack Redhat - (including) - (including)
Openshift_application_runtimes Redhat - (including) - (including)
Openstack_platform Redhat 13.0 (including) 13.0 (including)
Process_automation Redhat 7.0 (including) 7.0 (including)
Single_sign-on Redhat - (including) - (including)
Undertow Redhat * 2.2.24 (excluding)
Undertow Redhat 2.3.0 (including) 2.3.5 (excluding)

References